Multi-factor authentication (MFA) provides an additional layer of security during the login and authentication process by requiring a password and a verification code. Workiva supports two MFA methods: email-based MFA and app-based MFA (also called device MFA). Your organization's Org Security Admin determines which methods are available to you.
Note: You may be asked to re-authenticate using MFA. This can happen when there's an inactivity timeout or your organization implements a new login policy, for example.
Create a password
Org Security Admins manage all sign-in settings for the organization. To begin MFA setup, you'll need to create a password.
To create a password:
- Navigate to the welcome email that was sent to you, or go to the Workiva login page to reset your password.
- Enter your username and create a new password. Passwords must be at least 12 characters long and should not contain your first name, last name, or username.
- Click Save Changes.
Sign in using email MFA
With email MFA, you log in using your username, password, and a 6-digit code sent to your email. The code is valid for 10 minutes.
To sign in using email MFA:
- Go to the Workiva login page.
- Enter your username and password.
- Open your email to retrieve your 6-digit verification code.
- On the Identity Verification page, enter the 6-digit code.
- Click Continue. You're now logged into Workiva.
Sign in using app-based MFA (beta)
App-based MFA uses an authenticator app on your device to generate a 6-digit code at login. If your organization has app-based MFA enabled and you've registered a device, Workiva will use app-based MFA by default, even if email MFA is also enabled.
This feature is currently available to select customers as part of the app-based MFA preview. The preview feature is provided to you for technical testing and evaluation only to November 2, 2026. Workiva may extend the testing period of the preview features at its discretion. If your team is interested in using this feature, please contact your Customer Success Manager.
Set up your authenticator app
Before you can sign in with app-based MFA, you need to register your device through your profile settings.
To set up your authenticator app:
- Open a supported authenticator app on your device, such as Google Authenticator or Microsoft Authenticator.
- In Workiva, go to My Profile and select the Security tab.
- Click Change.
- Scan the QR code displayed in Workiva using your authenticator app or manually enter the setup key.
- Enter the 6-digit code from your authenticator app to confirm registration.
- Click Next. Your device is now registered.
Sign in using your authenticator app
Once your device is registered, Workiva uses your authenticator app for MFA at login.
To sign in using app-based MFA:
- Go to the Workiva login page.
- Enter your Username and Password.
- Open your authenticator app to retrieve the current 6-digit code.
- Enter the code.
- Click Next to log into Workiva.
Remove your authenticator app
To remove your authenticator app registration:
- In Workiva, go to your Profile settings.
- Find your registered authenticator app and select the option to remove it.
- Confirm the removal. Your account returns to the unregistered state.
Note: If you haven't registered a device, you'll see a reminder prompt each time you log in until setup is complete. If your org has app-based MFA enabled but no email MFA fallback, you have 3 login attempts before your account is locked out.
Configure MFA for your organization
Org Security Admins can enable and configure MFA options for all users in their organization through Organization Admin > Identity & access management > Authentication > Sign-in settings.
The following MFA options are available:
- Enable authenticator app-based MFA: Allows users with a registered device to use their authenticator app at login. (beta)
- Enable email-based MFA: Sends a 6-digit code to the user's email at login.
You can enable either option or both. The following table shows how Workiva handles each combination:
| App-based MFA enabled | Email MFA enabled | User has device registered | Outcome |
|---|---|---|---|
| No | Yes | No | Email MFA |
| Yes | No | No | 3 login attempts allowed (email MFA), then lockout |
| Yes | Yes | No | Email MFA |
| No | Yes | Yes | App-based MFA |
| Yes | No | Yes | App-based MFA |
| Yes | Yes | Yes | App-based MFA |
Set MFA frequency
Use the Require users to authenticate using MFA dropdown to set how often users must complete MFA. The maximum interval is 30 days.
Reset a user's MFA
You can reset MFA for any user at any time, regardless of their current MFA status. Use the Reset MFA button in Organization Admin or workspace settings when selecting a user.