Skip to content
Admin & Security

How to set up MFA for your team in HelloGrowthCRM

Enforce multi-factor authentication (MFA) for your HelloGrowthCRM workspace. TOTP, SMS, and security keys supported.

8 min readUpdated 12 Jun 2026
intermediate
Harnish ShahHarnish Shah

What this guide helps you do

Follow this article when you want a focused, step-by-step path to complete the task without digging through menus.

Need a broader overview first?

Go back to the Admin & Security section to browse more guides, compare related tasks, and choose a better starting point.

View all Admin & Security guides

MFA is the highest-impact security control. Supports TOTP (Google Authenticator, Authy), SMS, and FIDO2 security keys.

How to use this guide

Read the intro to confirm this is the right workflow, complete the steps in order, then review the common issues and related articles if your setup behaves differently from the standard path.

What you'll need

  • Owner role
  • Each user's phone for TOTP
  • 10 minutes for workspace setup; ~2 mins per user
  1. 1

    Settings → Security → MFA

    Settings → Security → MFA.

  2. 2

    Pick policy

    Optional, Required for admins, Required for all, Required + grace period.

  3. 3

    Pick allowed methods

    TOTP (recommended), SMS, FIDO2.

  4. 4

    Enforce

    Click Enforce policy. Existing users see banner: Set up MFA in next 7 days.

  5. 5

    User setup

    Settings → Security → MFA → scan QR with Google Authenticator → enter 6-digit → save backup codes.

  6. 6

    Recovery codes

    Each generates 10 backup codes. One-time-use.

  7. 7

    Admin recovery flow

    If user loses phone, admin can reset. Audit-logged.

  8. 8

    SSO + MFA

    If using SSO, MFA at IdP level. CRM trusts IdP MFA.

  9. 9

    Audit MFA adoption

    Adoption: % of users with MFA on.

  10. 10

    Periodic re-verify

    High-sensitivity actions require re-MFA.

Frequently asked questions

SOC 2 / ISO requirement?

SOC 2 Type II requires MFA for admin access. We comply.

SMS less secure?

SIM swap risk. Use TOTP or security keys for high-trust roles.

Cost?

Free.

Backup codes if lost phone?

Yes — 10 one-time codes generated at setup.

API keys bypass MFA?

Yes — API keys for programmatic access. Treat like passwords.

Bulk enable for team?

Yes — workspace policy enforces.

Related articles

See it in product

Try it yourself

Start a 14-day free trial of HelloGrowthCRM — no credit card required. You'll have everything you need to follow this guide.

Still need help?

If this article does not match your account setup, rollout stage, or edge case, review more guides in Admin & Security or contact our team for direct help.

Harnish Shah
Harnish Shah· Co-Founder, HelloGrowthCRM

Harnish leads engineering at HelloGrowthCRM. He focuses on CRM architecture, AI agents, and integrations across calling, messaging, and revenue systems.

Connect on LinkedIn →