VOL IV · Nº 207FRIDAY · MAY 15 · 20261 FLAG OPEN
The RFPRoom Quarterly
Pinegate Software · published by uStack
Library · Security

LIB-SEC-022 — How is MFA enforced?

Last reviewed Mar 16, 2026 (5 months ago). Reuse count: 0.

Answer
Canonical answer maintained by the knowledge admin. Used by AI drafting to seed RFP draft v1.

MFA is mandatory for all internal accounts (TOTP, FIDO2/WebAuthn). Customer admins can enforce workspace-wide MFA; WebAuthn (Yubikey, Touch ID) is supported alongside TOTP and is required for super-admin actions.

Metadata
Category
Security
Status
Approved
Freshness
Fresh
Freshness policy
12 months
Last reviewed
Mar 16, 2026
Author
Rachel Murphy
Reuse count
0
Times drafted from
1
Used by drafts (1)
RFP questions that drafted from this library entry.
Acting as Nina Vega · VP salesswitch role →