Security and two-factor authentication
Enable or disable two-factor authentication in Interlinked and understand what the current Security tab shows about account access.
NEEDS VALIDATION
This page includes product areas with mixed maturity or conditional behavior. Verify the current UI and tenant state before using it as external operating guidance.
What the Security tab is for
Open Settings → Security to manage two-factor authentication (2FA) and
review the access-related information currently shown by the panel. You can
open it directly at /en/settings?tab=security.
2FA adds a verification step from an authenticator app in addition to the account’s normal sign-in method. It is useful for accounts that manage customer conversations, business records, agents, or billing.
Enable 2FA
- Open Security in Settings.
- Turn on the Two-factor authentication control.
- Scan the QR code with a compatible authenticator app.
- Enter the six-digit code currently shown by the app.
- Select Verify & Enable.
Keep the authenticator app available after setup. The panel confirms the enabled state only after the verification code is accepted.
Screenshot: Security tab showing the 2FA setup dialog with QR code, six-digit code field, and Verify & Enable action
Common authenticator apps may work with this flow, but use the app you trust and follow the exact instructions shown by the panel. Keep any recovery information the product explicitly provides in a secure place; do not store it in CRM notes or agent knowledge.
Disable 2FA
- Return to Security.
- Turn off the 2FA control.
- Complete the password confirmation requested by the panel.
- Confirm that the disabled state is shown only if you intend to remove the extra protection.
If you are switching authenticator apps, prepare the replacement before disabling the current protection. Re-enable 2FA as soon as the new setup is verified.
What Active sessions currently means
The Security page includes an Active sessions information area. It is currently an explanatory card rather than a visible list of devices or a session-revocation control. Do not assume that you can inspect or terminate individual sessions from this screen.
If the panel later exposes session actions, follow the labels and confirmation messages shown there. If you suspect unauthorized access now, change the credential through the applicable sign-in provider, enable 2FA, and use a verified support path without sending passwords or recovery codes.
NEEDS VALIDATION
Authentication behavior, recovery options, and session controls can change with the account service. The current Security screen and sign-in message are the source of truth.
Keep account security responsibilities clear
- Google sign-in credentials are managed in Google’s account-security experience; see Manage sign-in and password.
- Profile values belong in Account information.
- Notification controls are in Notification preferences.
- Workspace member access is managed in People, not through a shared account password.
Related in Interlinked
Connect this documentation topic to the relevant product, workflow, or commercial context.