verified · reviewed 2026-09-12
Account security and MFA
Required TOTP is enforced before access and refresh tokens are issued.
- Audience
- tenant-admin, staff
- Roles / plan
- Each membership has its own password and MFA flags. All plans.
- Menu
- Dashboard → Settings → Security, or Manage security settings where offered
Prerequisites
- An authenticator app
Google confirms the Google account. It does not satisfy LuraFlow TOTP. Password eligibility is per membership: a workspace without a local password cannot use password login for that row.
- Open Security settings for the membership you are using.
- Enrol TOTP and store recovery codes offline.
- Sign out and sign in again. If MFA is required, tokens appear only after a valid code.
Open this setting on luraflow.com — uses the safe login redirect. Never opens another tenant hostname.
Canonical: https://luraflow.com/docs/getting-started/account-security