This article is also available in:

Two-factor authentication in the Portal

Account security in the Portal lets you set the sign-in requirements for every organisation in your portal from one place. You choose which permissions require two-factor authentication at login, and the requirement applies to all organisations in the portal. The organisations cannot switch it off again.


What you can do with it


  • Require two-factor authentication for all users in the portal, or only for users with sensitive permissions.
  • Apply one security standard across all parishes without contacting each of them.
  • Let each organisation add stricter requirements of their own on top.



Availability


Account security in the Portal is available to customers with a portal, for example dioceses, deaneries and church networks that manage several parishes in ChurchDesk. Every organisation also has its own Account security page in the ChurchDesk Settings, which works independently of the portal.



Content




Rights and roles


  • Portal administrators: Can open Account security in the portal view and set the requirements for every organisation in the portal.
  • Organisation administrators: Can open Account security in their own ChurchDesk Settings. They can add further requirements, but they cannot remove or switch off what the portal requires.
  • All other users: Nothing to set up. They are asked for a verification code at login if their permissions require it.



Set two-factor authentication requirements for your portal


  1. Switch to the portal view with the "PORTAL" selector at the top of the screen.
  2. Select "Account security" in the left menu.
  3. In the "Requires 2FA" column, switch on the permissions that should require a verification code at login.


Your change applies immediately to every organisation in the portal.


You can choose between these permissions:


  • "All users" — every user in every organisation of the portal.
  • "Users with user administration permissions" — users who can manage other users.
  • "Access to People" — users who can open the People module.
  • "Access to Forms" — users who can open the Forms module.
  • "Access to Payments & Giving" — users who can open Payments & Giving.


INFORMATION: If you switch on "All users", the other permissions are covered automatically. They are then shown as inactive with the note that they are already covered.



How the requirements appear in the organisations


In each organisation, the same permissions are listed under ChurchDesk Settings > Account security. Everything the portal requires is switched on there and locked, with the note that it is required by your portal and cannot be changed in the organisation.


The requirements are additive:


  • The organisation can switch on further permissions for their own users at any time.
  • The organisation cannot switch off a permission that the portal requires.
  • If you do not switch anything on in the portal, each organisation decides for itself.


EXAMPLE: Your portal requires two-factor authentication for users with People access. A parish also wants it for Forms access, so they switch on that permission in their own settings. Both requirements now apply in that parish.


ChurchDesk checks the requirements at login and looks at the permissions the user has in that organisation. Users are asked for a verification code only once per login, even if several requirements apply to them.



Two-factor authentication and single sign-on


A verification code is only requested when a user signs in with email and password. Users who sign in with single sign-on, for example through their diocese, are never asked for a code, because the identity is already confirmed by the single sign-on provider.


NOTE: If most of your users sign in with single sign-on, switching on "All users" will affect fewer people than you expect. It only applies to sign-ins with email and password.



How your users receive their verification code


For more information, see the following article: Two-Factor Authentication with an App


What your users experience at the next login


Users who are affected by a new requirement do not have to do anything in advance. The next time they sign in with email and password, ChurchDesk asks them to confirm their email address with a six-digit code and then guides them through setting up two-factor authentication for their account. From then on, they confirm their login with a verification code.



Keywords: two-factor authentication, 2FA, MFA, multi-factor authentication, account security, portal security, sign-in requirements, verification code, login security, single sign-on, SSO, SMS code, security settings, enforce 2FA, portal

Updated on: 16/09/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!