User multi-factor authentication (MFA)
Table of Contents
As of Aug 4, 2025, all accounts without SSO or two-factor authentication (2FA) already enabled will have 2FA enabled for their accounts. This adds an additional layer of protection for all accounts.
While two-factor authentication (2FA) will be the minimum standard for account security, Single Sign-On (SSO) is our recommended account access setup, if available.
Users not impacted
All accounts except the following will be impacted:
- Basic/Limited users
- Users that sign in via SSO
Two-factor authentication logic
After this feature is auto-enabled, the following logic will apply to your account:
- The contact method used for two-factor authentication will be email address. The email address stored on each user's profile will be used to send authentication emails to the user.
- The password reset interval will be set to 90 Days. This ensures that your team members reset their passwords regularly.
- Users will remain logged in 8 hours (if previously undetermined) after they are inactive in the CEM. After this timeframe, the user will be logged out of the system and must re-authenticate themselves by logging in with their email address and password.
For accounts created after August 4, 2025, the above settings will be the default selections if you are not utilizing Single Sign-On (SSO).
User experience
The first time that a user logs in with a username and password on or after August 4, 2025, they will then receive a one-time passcode via the email associated with their user account, which they will then use to authenticate their account login.
After this initial authentication, a user will need to log in to the system each time they reach the end of their inactive session (default of 8 hours).
Verification code SMS autofill
When completing 2FA on a supported mobile device (iOS or Android), users can use the automated keyboard suggestion to instantly enter their verification code. This feature is available across the Paradox Native App and all Paradox web pages.
Troubleshooting tips
If your users are not receiving verification codes for MFA, then it most likely is due to one of the below reasons:
- User is unsubscribed.
- User has filtered olivia.alerts@paradox.ai emails and can’t find them in their inbox.
After checking the above scenarios, we encourage you to contact your CS Representative for further troubleshooting.