How to Set Up Multi-Factor Authentication (MFA)
MFA is optional and stays off until an administrator turns it on. Here is how to enable it for your organization, set a grace period, and add your own authentication method.
What MFA does
Multi-factor authentication adds a second step when someone logs in to Graphium. After entering an email address and password, the user confirms it is really them with a one-time code or an authenticator app.
MFA is optional. It stays off until an administrator at your organization turns it on. Nothing changes for you or your users until you decide to enable it.
- Who can turn it on: an organization administrator
- How long it takes: a few minutes to configure, plus a minute or two per user to set up their method
- Where it applies: the Graphium web application
MFA is enabled per organization. If your users belong to more than one organization in Graphium, turning it on for one does not turn it on for the others.
Once MFA is on, every user in your organization is prompted to set up a method the next time they log in, unless you set a grace period first.
MFA methods are tied to a user's login account, not to one organization. If a user has already set up a method, they can use it again here as long as your organization allows that method.
Step 1: Open MFA settingsLog in as an organization administrator, click the gear icon in the top right, and choose MFA Settings. If you do not see MFA Settings, your account is not set as an administrator. Contact your Graphium point of contact and we will get that sorted out.
Step 2: Review the policy screenEverything for MFA lives on one screen. Out of the box, MFA is unchecked and nothing is being enforced.

The Organization MFA policy screen before anything is turned on.
Step 3: Enable MFA and set a grace periodCheck Enable MFA for this organization. This is the master switch for your whole organization.
Then decide on a grace period. Check Enable grace period and a Grace period end date field appears. Users may continue logging in without MFA through the date you select. MFA is required starting the next calendar day at 12:00 AM Central Time.
A grace period gives your team a window to get set up on their own schedule instead of hitting the prompt cold at their next login. If you have users who only log in occasionally, give yourself more runway than you think you need.
Step 4: Decide about remembered devicesCheck Enable remembered browsers and devices and a Remembered device duration (hours) field appears. Users can then choose to remember a browser or mobile device after they complete MFA, and they will not be prompted again until that many hours have passed. The default is 24 hours.
Worth thinking through if your users share workstations, since a remembered browser on a shared machine skips the second step for whoever sits down next.
Step 5: Choose the allowed methodsPick which methods your users are allowed to use. You can allow one, two, or all three.
- Email. A one-time code is sent to the user's verified account email address. Nothing to install and nothing extra to carry.
- Text message. A one-time code is sent by SMS. Requires a mobile number and cell service at login.
- Authenticator app. The user generates a code in an app such as Google Authenticator, Microsoft Authenticator, or 1Password. Works without cell service, which matters in facilities with poor coverage.
If you are not sure where to start, allowing all three gives your users the most flexibility and creates the fewest support calls.
Step 6: Save your policyClick Save settings. Your policy takes effect immediately, subject to the grace period you set.

A completed policy: MFA on, a grace period through September 30th, remembered devices for 24 hours, and all three methods allowed.
How users set up their own MFA methodAny user can set up or change their own methods at any time, before or after your organization turns MFA on. Click the gear icon, then go to the user profile. The Multi-factor authentication section sits below the profile details.

The user profile screen before any method is set up.
Option 1: Use the account email
This is the fastest option and requires nothing new. Check Use for MFA next to the account email address, and one-time codes will be sent there at login.

The account email enabled as an MFA method.
Option 2: Add an authenticator app
Click Add MFA method and choose Authenticator app. This is the most secure of the three options.

Choosing the authenticator app option.
Open your authenticator app first and create a new account or profile there. Then click Generate QR code, scan the code with your app, enter the six digit code your app displays, and click Verify authenticator code. If your app cannot scan a code, use Show manual setup details to enter the key by hand.

Scan the QR code with your authenticator app, then enter the code it gives you to finish.
Option 3: Add a text message number
Click Add MFA method and choose Text message. Enter your mobile number and click Send code, then enter the code you receive to confirm the number.

Adding a mobile number for one-time codes by text.
You can set up more than one method. Having a second method on file is a good idea in case you do not have your phone with you.
Common questions
Do we have to use MFA? No. It is optional and off by default. If you do nothing, nothing changes.
Can we turn it off after we turn it on? Yes. An administrator can uncheck Enable MFA for this organization and save.
Can we require MFA for some users but not others? The policy applies to everyone in the organization. There is no per-user setting.
What happens if a user loses their phone or gets locked out? Submit a ticket through the support portal and we will help get them back in. It is also a good idea to have users set up a second method, so they have a backup if their phone is not handy.
Need helpIf you would like us to walk your administrator through the setup, or you want to talk through whether MFA makes sense for your group, contact your Graphium point of contact or submit a ticket through the support portal.