Managing Multi-Factor Authentication (MFA) as the Master User
How Master Users enforce, monitor and reset multi-factor authentication for users in Reapit Connect.
Overview
As the Master User for your organisation, you control the multi-factor authentication (MFA) policy in Reapit Connect and can reset MFA for staff who lose access to their authenticator. This article covers:
- Enforcing MFA for your organisation
- Checking who has MFA enabled
- Resetting MFA for a user
- MFA and the Master User account
Enforcing MFA for your organisation
- Sign in to the Reapit Connect admin portal as the Master User.
- Navigate to Security › MFA Policy.
- Choose the enforcement level:
- Optional — users may enable MFA themselves but are not required to.
- Required for financial roles — users with trust accounting or payment permissions must enrol.
- Required for all users — every user must enrol at their next sign-in.
- Set a grace period (0 to 14 days). Users who have not enrolled when it ends are blocked from signing in until they do.
- Select Save policy. Affected users are notified by email.
Tip: Announce the change internally before saving, and set a 7-day grace period. Most lockout tickets come from users who missed the notification email.
Checking who has MFA enabled
- Navigate to Users in the admin portal.
- The MFA column shows each user's status: Enrolled, Not enrolled or Reset pending.
- Filter by Not enrolled to chase stragglers before a grace period ends, or export the list for a compliance record.
Resetting MFA for a user
Reset MFA when a user has lost their phone and has no recovery codes:
- Verify the person's identity first — speak to them directly or via a known phone number, never based on an email request alone. MFA reset requests are a common social-engineering technique.
- In Users, open the user's profile and select Reset MFA.
- Confirm the reset. The user's existing enrolment and recovery codes are invalidated immediately.
- The user is prompted to enrol again at their next sign-in. The reset is recorded in the audit log with your name and timestamp.
MFA and the Master User account
- The Master User account must always have MFA enrolled, regardless of the organisation policy.
- Store the Master User's recovery codes securely — for example, in the office safe — separate from the phone used for codes.
- If the Master User is locked out, only Reapit support can reset the account, and additional identity verification applies. Nominate a backup administrator to avoid this becoming urgent.