Set up 2-Step Verification

Enforcement

2-Step Verification screenshot

 

 

 

 

 

 

 

Before enforcing 2-Step Verification, make sure all of your users and administrators are enrolled in 2-Step Verification. You can place users not yet enrolled in 2-Step Verification into exception groups so they will not be locked out of their Google Apps accounts when you enable 2-Step Verification enforcement.

After you've enabled 2-Step Verification enforcement, when you create new user accounts, you will need to place these new users into an exception group so they can access their Google Apps account and enroll in 2-Step Verification.

Follow the instructions here to make 2-Step Verification mandatory:

  1. If you will require 2-Step Verification of all users in the domain or within an existing organizational unit (OU), you may skip this step. If you need to have a different 2-Step Verification setting for a select group of users within an organization, create an admin-managed group containing all such users. See Use exception groups for detailed instructions on creating custom groups.
  2. On the Dashboard, click Reports, then select Additional Reports.
  3. Click Download under 2-Step Verification Enrollment Report. Please note this report is available only if you allowed users to turn on 2-factor authentication as described in Set up 2-Step Verification for your domain.
  4. Examine the CSV file and ensure all users to be forced into 2-Step Verification are already enrolled in it, indicated by "true" in the enrolled_2-step_verification column, like so:
    account_name, enrolled_2-step_verification, enforced_2-step_verification "bart@example.com", true, false
  5. On the dashboard, click Security > Basic settings > Enforce 2-Step Verification on users.
  6. Select the organization where you wish to make 2-Step Verification mandatory. Then select Turn on enforcement.
  7. To have a suborganization inherit the 2-Step Verification setting from its parent organization, click the Use inherited button that appears near the right margin when you hover over the Authentication pane.
  8. If you would like to exempt a group of users, select the group name (created in step 1) on the right-hand side keeping the organization selected on the left-hand side of the page and select Turn off enforcement. This will apply 2-Step Verification to all users in the selected organization except the users in the exception group.
  9. Save your changes.

    All users of the selected organization are now required to enter a secondary code from their mobile device.