Overview
Two-Factor Authentication (2FA) adds an additional security layer beyond username and password. Users must provide a second factor - typically a time-based one-time password (TOTP) from an authenticator app - to access Forest.Supported 2FA methods
Authenticator apps (recommended)
Time-based One-Time Password (TOTP) apps generate 6-digit codes that change every 30 seconds:Google Authenticator
Microsoft Authenticator
Authy
1Password
Bitwarden
LastPass Authenticator
Backup codes
Recovery codes to use if you lose access to your authenticator app:- Generated during 2FA setup
- One-time use only
- Store securely (password manager or printed copy)
- Can regenerate if needed
Enabling 2FA (for users)
Setup process
Access Account Settings
Enable Two-Factor Authentication
Scan QR Code
- Open your authenticator app
- Tap “Add account” or ”+” button
- Scan the QR code displayed in Forest
Verify Setup
Save Backup Codes
- Download or copy your backup codes
- Store them securely (password manager recommended)
- Check the box to confirm you’ve saved them
2FA Enabled
Manual setup key
If you can’t scan the QR code, use the manual setup key:Using 2FA to log in
Login flow
Enter Credentials
Enter 2FA Code
Remember Device (Optional)
Access Granted
Using backup codes
If you don’t have access to your authenticator app:Click 'Use Backup Code'
Enter Backup Code
Code is Consumed
Trusted devices
Mark devices as trusted to skip 2FA for 30 days:- Use Case: Your primary work computer
- Security: A secure cookie identifies the device
- Removal: Go to Account Settings > Security > Trusted Devices to revoke
Enforcing 2FA (for admins)
Administrators can require 2FA for all users or specific roles.Project-wide enforcement
Require 2FA for everyone:Navigate to Security Settings
Enable 2FA Requirement
Set Grace Period
- 24 hours (urgent)
- 7 days (recommended)
- 30 days (gradual rollout)
Notify Users
Monitor Compliance
Role-based enforcement
Require 2FA only for specific roles:- Go to Project Settings > Roles
- Edit each role
- Check Require 2FA for this role
Exceptions
Allow specific users to bypass 2FA requirement:- Use Case: Emergency access accounts, service accounts, external contractors
- Configuration: Edit user profile > Security > Exempt from 2FA requirement
Managing 2FA
Regenerating backup codes
If you’ve used all your backup codes or lost them:Access Security Settings
Regenerate Codes
Enter 2FA Code
Save New Codes
Resetting your own 2FA
If you need to switch authenticator apps or devices:Disable 2FA
Verify Identity
Re-enable 2FA
Admin: resetting user’s 2FA
If a user loses access to their authenticator and backup codes:Verify User Identity
Navigate to User Management
Find User
Reset 2FA
Confirm Action
Log the Action
2FA + SSO
How they work together
2FA and SSO can be used simultaneously for defense in depth:- IdP-Based 2FA (Recommended)
- Forest 2FA + SSO
- SSO Only (No Forest 2FA)
- User authenticates with IdP (e.g., Okta, Azure AD)
- IdP requires MFA (push notification, TOTP, etc.)
- Forest trusts the IdP’s authentication
- Centralized MFA management
- One MFA prompt for all applications
- Better user experience
Recommended configuration
For SSO Users
For Password Users
Troubleshooting
Code not working
Time Sync Issues
Time Sync Issues
- Check your phone’s time settings
- Enable automatic time/date
- Try the next code (they change every 30 seconds)
- Go to Settings > Time correction for codes > Sync now
Wrong Code Entered
Wrong Code Entered
- Wait for the code to refresh in your app
- Ensure you’re using the correct account (if you have multiple)
- Check for typos (0 vs O, 1 vs l)
Authenticator App Deleted
Authenticator App Deleted
- Use a backup code if you have one
- Contact your admin for 2FA reset
- Admin must verify your identity before resetting
Can’t scan QR code
Solutions:- Use Manual Entry: Copy the setup key and enter it manually in your authenticator app
- Try Different Device: Use a tablet or another phone to scan
- Check Camera Permissions: Ensure authenticator app has camera access
- Screenshot: Take a screenshot (secure it afterwards) and scan from photos
Lost backup codes
If you still have authenticator access:- Log in with your authenticator code
- Regenerate new backup codes
- Save them securely
- Contact your administrator
- Admin will verify your identity
- Admin can reset your 2FA
- Set up 2FA again immediately
Can’t log in after 2FA enforcement
Problem: 2FA was enforced but user hasn’t set it up Solution:- Users receive grace period to enable 2FA
- During grace period, they’re prompted to set up 2FA
- After grace period, they must set up 2FA before accessing
- Admin can temporarily exempt user from 2FA requirement
- User can then log in and set up 2FA properly