Allow more 2FA Options
planned
N
Nigel Moore
Whilst the recent enforcement of 2FA (via email) is a welcome addition to the security of High-Level, email based 2FA is unfortunately one of the least secure 2FA methods.
So, please add more 2FA options.
Including at a minimum TOTP codes (a global standard) that people can use through whatever TOTP App they use.
(E.g. Authy, Duo, Google Authenticator, Microsoft Authenticator etc).
And at the same time, please:
- Allow an agency to select what 2FA options they will allow to be used across their clients.
- Allow Admins of a sub-account to also have this level of functionality to select what 2FA options users in their Sub-Account can use IF the Agency gives it to them.
Log In
G
G J
Sales & Marketing: Add 2FA using:
-> OTP apps (Google / MS Authenticator etc)
-> Security keys
- Hardware-based
- LC mobile app-based
- Phone-based (iCloud / Google account)
- Trusted device-based (such as a Mac / PC - Google, Stripe, etc all do this)
Remove Email & Text OTP
D
Damien Harrison
Rather than simple MFA an option should exist to use SSO providers such as Microsoft or Google allowing use of conditional access policies etc.
M
Marcus Sutherland
Any progress on this at all? This is a critical security issue and should be resolved. No proper 2FA in 2024 is just...... It should be required for every user and login, as the system contains sensitive information such as names, addresses, payment details... etc.. Please prioritise.
J
Jared Fu
As a digital agency working with multiple clients, security is a top priority for us. Implementing Two-Factor Authentication (2FA) across both agency and sub-accounts in GoHighLevel is crucial for several reasons:
We handle sensitive client data, including personal information, campaign details, and performance metrics. 2FA provides an added layer of security that helps prevent unauthorized access, ensuring that our clients' data remains secure.
Many industries are governed by strict data protection regulations. By offering 2FA, GoHighLevel can help agencies like ours comply with these regulations and avoid potential penalties.
Cyberattacks, including phishing and credential stuffing, are on the rise. 2FA makes it significantly harder for malicious actors to gain access to our accounts, reducing the risk of data breaches.
Security breaches can severely damage an agency's reputation. By implementing 2FA, GoHighLevel would demonstrate a commitment to security, helping agencies build and maintain trust with their clients.
With multiple team members and clients accessing GoHighLevel, enforcing 2FA helps ensure that everyone adheres to the same high security standards, reducing the likelihood of weak points in the system.
To maximize the effectiveness of 2FA, I recommend GoHighLevel support popular authentication apps like Google Authenticator, Authy, and Microsoft Authenticator. These apps are widely used and trusted, offering a convenient and secure way to manage 2FA codes. By integrating with these apps, GoHighLevel can provide users with a reliable and flexible solution for securing their accounts.
Given the importance of security in our industry, I strongly urge GoHighLevel to prioritize the implementation of 2FA with support for these authentication apps across all accounts. This feature would not only enhance security but also position GoHighLevel as a leader in protecting its users' data.
D
David Lee
For the love of all things holy, please add authenticator app support. 2FA by email is painful, and the web interface is poorly coded as it refreshes the 2FA input screen making you think you have to do it again, when it's just a delay.
The question for HighLevel is whether or not this is going to make a revenue difference, and the answer is yes. Greater satisfaction and ease of use makes for happier clients and good word-of-mouth.
Email 2FA is also far more susceptible to being hacked, and that never ends well for anyone (and negatively impacts revenue).
Thank you!
J
Juan Hernandez
Can the 2FA be added that is optional for some users? have users that are having issues for it to work. or have an authenticator option? thanks.
N
Nigel Moore
Juan Hernandez I would strongly recommend against optional 2FA for a CRM. It should be required (as it currently is) for all users.
We just want High-Level to add TOTP as an option, in addition to the Email & SMS options.
The existing email 2FA has been extremely reliable for us over the past few years, if you have users having issues, ask them to shoot in a support ticket.
Cheers, Nigel 🤓
J
Jay Andy
This is vital! 2FA with Google Authenticator's algorithm we can use any number of 2FA clients.
J
Julie Bel Conner
Yes!
J
Jamie Righter
Yes please!
J
John Britt
Some form of authenticator app for me please.
Load More
→