Provide 2FA
complete
Marek Brzeziński
I think additional layer of security is needed in an application that gathers that much of the information. I wouldn't like anyone to get access to my data. Simple two-factor authentication should be added.
Alex Cunningham
updated the status to
complete
This is live! Two-factor authentication is available now.
Turn it on from Settings > Account Management, scan the QR code with your TOTP app, and confirm one code to enroll. It's enforced on every login path (email/password, Google, Microsoft, SSO) on web, desktop, and mobile.
You'll get ten single-use backup codes when you enroll. Keep those somewhere safe, since they're shown once and are what get you back in if you lose your authenticator.
More detail here: https://help.sunsama.com/docs/settings/user-settings/#two-factor-authentication
Alex Cunningham
updated the status to
complete
This is live! Two-factor authentication is available now.
Turn it on from Settings > Account Management, scan the QR code with your TOTP app, and confirm one code to enroll. It's enforced on every login path (email/password, Google, Microsoft, SSO) on web, desktop, and mobile.
You'll get ten single-use backup codes when you enroll. Keep those somewhere safe, since they're shown once and are what get you back in if you lose your authenticator.
Michael Lasmanis
Given that Sunsama aggregates (with full read/write privileges) multiple systems that in almost all cases have 2FA enabled (gsuite office365, etc), not having 2FA completely defeats the purpose of having 2FA enabled on those platforms for your users.
Additionally, given the type of users who uses Sunsama (exec/manager/team lead/etc) and the highly sensitive nature of the information contained in the systems you have access too (once again think gsuite, office365 etc), Sunsama would be a very valuable single point of compromise for those accounts and the vast amount of corporate (and personal data) contained within .
I'd highly suggest implementing TOTP (https://en.wikipedia.org/wiki/Time-based_one-time_password) at a minimum.
Ideally support for the following items would be considered best practices in 2024:
- FIDO2 security keys (yubikey, google titan, etc)
- Passkey support
Thanks
Michael
Tiago Ferreira
Is there any planning for providing 2FA feature in the Sunsama? That's extremely important.
Scott Ames
+1 here - this feature will likely stop me from using Sunsama. Very surprising this isn't a feature given the high price point.
Matt Lovett
Sunsama is the home to important data I am really surprised this is not yet a feature?
Paul P
Completely agree with this! +1 vote, thanks for the suggestion.