Two-factor authentication (2FA) adds a second step to sign-in. After entering a password, the person confirms a one-time verification code. This protects accounts against stolen or guessed passwords.
2FA on Vome can cover administrators, end users, or both. For each group it can either be required or simply offered. Requiring it for administrators is the usual recommendation, because those are the accounts with the most access.
Availability: 2FA is available on the Enterprise and Ultimate plans. On lower plans, the 2FA settings are locked and display an "Available on Enterprise" notice.
Two methods are available:
Each person uses one active method at a time, either an authenticator app or SMS, not both. Setting up an authenticator app makes it the active method, and the phone option is set aside (it stays on file but is not used). Removing the authenticator app switches SMS back on automatically.
Go to Settings > Security > Two-Factor Authentication (2FA). You will see a Phone Number section and an Authenticator app section.
To move from SMS to an authenticator app, simply set up the authenticator app and it takes over. To go back to SMS, remove the authenticator app and your phone number is used again, with no need to re-enter it.
When you set up an authenticator app, you receive 10 one-time backup codes. Each code works once if you ever lose access to your authenticator app. From the 2FA settings, you can download them, copy them, or regenerate a fresh set (regenerating invalidates the old set).
Please note: backup codes come with the authenticator app method. If you only use SMS, your recovery path is to receive a new code by text using the "Resend" option. If someone loses both their authenticator app and their backup codes, they will need to contact support to regain access, as there is no self-serve reset.
Access is not granted until the code is verified. The second factor is enforced on our servers, not just in the app.
There are three sensible positions, and most organizations pick the first.
| Choice | What it means | When to pick it |
|---|---|---|
| Required for administrators (recommended) | Every admin must use 2FA. End users may still turn it on themselves. | The accounts with the most access are protected, and you are not asking your whole database to set up a second factor. |
| Required for everyone | Administrators and end users must all use 2FA. | Strongest, and worth it where profiles hold sensitive information. Expect some support requests from people changing phones. |
| Offered, not required | 2FA is available to anyone who wants it, and nobody is forced. | Lowest friction. In practice very few people turn it on themselves, so treat this as close to having no 2FA. |
Requiring 2FA for administrators and offering it to end users is the combination most organizations land on.
Organization-wide enforcement is controlled only by the Account Holder of the organization, and only on the Enterprise or Ultimate plan. Other admins, and Account Holders on lower plans, do not see this control.
Go to Settings > Security > Two-Factor Authentication (2FA) and scroll to the Organization-wide enforcement section at the bottom. There you will find:
What happens when enforcement is turned on:
Turning enforcement off stops requiring it. Anyone who set up 2FA keeps it unless they remove it themselves.
Attention: people signing in on an older mobile app version may be unable to complete sign-in until they update. Make sure your team is on the latest app before you turn enforcement on.
This is the most commonly missed part of the picture, and it matters most when 2FA is optional or off for end users.
By default, signing in to Vome is single factor: an email address plus a password. 2FA is what adds a second step on top of that.
But people do not have to create a Vome password at all. They can create an account with social sign-on, using Continue with Google, Continue with Microsoft or Continue with Apple. For those accounts:
Attention: this means you cannot guarantee a second factor for every end user through Vome alone. If someone signed up with Google and has no 2FA on their Google account, that account is protected by a single password held elsewhere. Vome can neither see nor change that.
The practical takeaway: 2FA settings in Vome govern password-based logins. Social sign-on accounts inherit whatever their provider enforces.
Enterprise SSO is a different thing from the social sign-on described above. If your organization uses enforced SSO, admins sign in through your identity provider (Microsoft Entra, Google Workspace, and similar), which handles its own multi-factor security. App-level 2FA does not additionally apply to SSO logins, because SSO is treated as the secure path. 2FA enforcement applies to password-based logins.
Yes. Everything above works in the web app and the mobile app. People can complete the verification step, and the required first-time setup, on either one. Organization-wide enforcement is configured by the Account Holder on the web settings page.