Security
The Security settings page controls multi-factor authentication (MFA) requirements for your organization. Navigate there via Settings → Security.

MFA Policy
Require MFA for all users
When this toggle is enabled, every user in your organization must set up MFA before they can access Evenpay. Any user who hasn't configured MFA yet will be prompted to do so immediately after signing in — they won't be able to proceed until it's set up.
This is a strong setting to enable, especially for organizations handling sensitive compensation data. We recommend turning it on once your team has been notified so they can prepare.
Allowed MFA Methods
Choose which authentication methods users can use to satisfy MFA. Both methods can be enabled simultaneously, allowing each user to choose their preferred option:
Method | How it works |
Authenticator App | Users generate a time-based one-time code using an app like Google Authenticator or Authy. No phone number required. |
SMS Verification | A one-time code is sent to the user's mobile number via text message each time they log in. |
Enrollment Status
The Enrollment Status section shows which users in your organization have set up MFA and which haven't. Click Refresh to load the latest enrollment data.
This view is useful for checking compliance with your MFA policy — particularly after enabling the "Require MFA for all users" toggle, when you want to confirm that everyone has completed setup.
Frequently Asked Questions
What happens if a user hasn't set up MFA and I enable the requirement?
They'll be prompted to set it up on their next login. They won't be able to access Evenpay until MFA is configured, so it's worth giving your team advance notice before enabling the requirement.
A user has lost access to their authenticator. How do I help them?
As an Owner or Administrator, you can reset a user's MFA configuration from their profile. They'll then be prompted to set up MFA again on their next login.
Should I use Authenticator App or SMS?
Authenticator apps are generally considered more secure than SMS (which can be vulnerable to SIM-swapping attacks). We recommend allowing both but encouraging users to use an authenticator app where possible.
Is it possible to have other authentication methods (eg. Microsoft Entra ID)
Yes, if you need to set up specific authentication method, reach out to Evenpay support in order to do this.
Updated on: 08/04/2026
Thank you!
