Two-Factor Authentication (2FA)

Edited

To keep your account secure, we support Two-Factor Authentication (2FA).

Adviser 2FA Settings

✅ When an adviser enables 2FA:

  • 2FA is enabled for the professional forever

❌ When an adviser disables 2FA:

  • This is not possible, when 2FA is enabled for a professional it is on forever.


Firm 2FA Settings

✅ When a firm enables 2FA for professionals:

  • 2FA is enabled for all existing professionals in the firm.

  • Any new joiners to the firm will have 2FA automatically enabled.

  • Any professionals leaving the firm keep 2FA enabled. They may disable it, unless their network still requires it.

❌ When a firm disables 2FA for professionals:

  • Existing professionals keep 2FA enabled.

  • New professionals joining will retain their current 2FA setting:

    • 2FA is enabled if either the firm or network requires it.

    • 2FA stays disabled only if both firm and network disable it.


Network 2FA Settings

✅ When a network enables 2FA:

  • 2FA is enabled for all professionals in the network.

  • New professionals joining must have 2FA enabled.

  • Professionals leaving the network keep 2FA enabled, but can disable it unless their firm still requires it.

❌ When a network disables 2FA:

  • Existing professionals keep 2FA enabled.

  • New joiners to the network keep their current 2FA setting.


Professional Movement Scenarios

👤 A professional moves to a new firm:

  • If the new firm requires 2FA, it is enabled for the professional.

  • If the new firm doesn’t require 2FA, and the network still does, 2FA is enabled.

  • If both firm and network have 2FA disabled, 2FA is enabled.

🆕 A professional is newly created:

  • If created in a firm that requires 2FA, it is enabled.

  • If created in a firm that does not require 2FA, but the network does, 2FA is enabled.

  • If both firm and network have 2FA disabled, 2FA is enabled.


Firm Movement Scenarios

A firm joins a new network:

  • If the new network requires 2FA, it is enabled for all professionals in the firm.

  • If the new network does not require 2FA, no changes are made.

A new firm is created:

  • 2FA isn’t set yet (no professionals).

  • The firm’s 2FA setting is inherited from the network.

Two-Factor Authentication (2FA) for firm admins

This guide explains how 2FA behaves for firm admins, based on whether it's enforced by a firm or a network.


🏢 Firm Enforces 2FA for Admins

When a firm decides to enforce 2FA for its firm admins:

Enforcing 2FA (Set by a VF Admin in Nellie)

  • All current firm admins (both active and allowed) for that firm have their 2FA type set to EMAIL.

New Firm Admins

  • Any new firm admin created for a firm that enforces 2FA will automatically have their 2FA type set to EMAIL.

Existing Admin Gets Firm Access

  • If an existing admin gains access to a 2FA-enforced firm, their 2FA type is updated to EMAIL.

Turning Off 2FA Enforcement

  • Existing admins keep 2FA (EMAIL) even after enforcement is turned off, unless manually reverted to NONE (which is not recommended).

  • New admins created after enforcement is turned off will have 2FA type set to NONE, unless another firm or network they access still enforces 2FA.


🌐 Network Enforces 2FA for Admins

When a network chooses to enforce 2FA for firm admins who access it (or its firms):

Enforcing 2FA (Set by a VF Admin in Nellie)

  • All current firm admins with access to the network (or its firms) have their 2FA type set to EMAIL.

New Firm Admins

  • Any new firm admin with access to a network (or firm within the network) that enforces 2FA will automatically have their 2FA type set to EMAIL.

Existing Admin Gets Network Access

  • If an existing firm admin is granted access to a network (or one of its firms) that enforces 2FA, their 2FA type is set to EMAIL.

Turning Off 2FA Enforcement

  • Existing admins retain their 2FA type set to EMAIL.

  • New admins created after enforcement is turned off will have 2FA type as NONE, unless they access another firm or network that enforces 2FA.


🔄 Key Takeaways

Scenario

Will Admin Have 2FA (EMAIL)?

Firm or Network Enforces 2FA

✅ Yes

Firm or Network Turns Off 2FA

🚫 New admins: No

Existing admins: Yes (unless reverted)

Admin gets new access to a 2FA-enforcing firm/network

✅ Yes

Admin is created in a 2FA-enforcing firm/network

✅ Yes


Was this article helpful?

Sorry about that! Care to tell us more?

Thanks for the feedback!

There was an issue submitting your feedback
Please check your connection and try again.