Onit Documentation

Mandatory Multi-Factor Authentication (MFA) Coming January 31, 2026

by Sigmarie Soto Updated on

Beginning January 31, 2026, Multi-Factor Authentication (MFA) will be required for all accounts. This change is part of our ongoing commitment to protect your data and maintain the highest security standards. 

What You Need to Know

MFA adds an extra layer of security to your account by requiring more than just a password to sign in. This significantly reduces the risk of unauthorized access, even if your password is compromised. 

Setting Up MFA

You can set up MFA here using one of the following methods:

  • Authentication App (Recommended): Use a dedicated authenticator application (such as Google Authenticator, Microsoft Authenticator, or Authy) on your mobile device or computer.
  • SMS (Text Message): Receive a verification code via text message to your mobile phone. 

Important Requirements

MFA is mandatory and cannot be disabled or bypassed (with one exception, see the FAQ section below). This requirement applies to all users to protect data and maintain our security standards. All users must have at least one supported MFA method configured in order to access the platform. Accounts without MFA enabled will be prompted to set up MFA after January 31st

Device Options

We understand that some users may not be issued a company mobile phone or may be unwilling to use a personal device. In these cases, SMS to a personal phone is not the only supported option. Users may instead configure an authenticator application on a company-issued laptop or desktop device, where permitted by internal policy. 

This flexibility ensures that all users can comply with the MFA requirement while respecting individual preferences and company policies regarding device usage. 

Action Required

Please set up MFA on your account before January 31, 2025 to ensure uninterrupted access to the platform. You can configure MFA in your account settings at any time. 

Frequently Asked Questions (FAQs)

Expand or collapse content Q: When does the MFA requirement go into effect?

MFA will be mandatory for all accounts starting January 31, 2026. After this date, accounts without MFA enabled will not be able to authenticate. We will be running a migration throughout the week and project to be fully transitioned by February 6, 2026. 

Expand or collapse content Q: Can I disable MFA after setting it up? 

No. MFA is a mandatory security requirement and cannot be disabled or bypassed (one exception). The administrator no longer has the ability to disable MFA from the data room.

Expand or collapse content Q: Can I temporarily disable MFA after setting it up? 

Yes, the administrator has the ability to pause 2FA for up to 7 days. 

Expand or collapse content Q: What if I don't have a company-issued mobile phone? 

You have options! You can use SMS to a personal phone number, or you can configure an authenticator application on a company-issued laptop or desktop device (where permitted by your internal policy). The authenticator app option provides flexibility for users who prefer not to use personal mobile devices.

Expand or collapse content Q: Which authenticator apps are supported? 

Most standard authenticator applications are supported, including Google Authenticator, Microsoft Authenticator, Authy, and other TOTP-based authenticator apps. You can use these apps on either a mobile device or a desktop/laptop computer.

Expand or collapse content Q: What happens if I don't set up MFA by January 31, 2026? 

Accounts without MFA enabled will be unable to authenticate into a room after the deadline. You will need to set up MFA when you attempt to login.

Expand or collapse content Q: What if I lose access to my MFA device?

Reach out to your room Administrator to pause MFA or reset MFA.

Expand or collapse content Q: What if I am sharing username and password with colleagues and we don't have a shared MFA device? 

Sharing account credentials is not recommended for security and compliance reasons, as it makes it impossible to track individual user actions and maintain proper access controls. For shared access scenarios, we recommend splitting the shared account into individual accounts.

Expand or collapse content Q: Will this affect my current access? 

Your current access will not be affected until January 31, 2026. However, we strongly recommend setting up MFA as soon as possible to familiarize yourself with the process and ensure a smooth transition.

Expand or collapse content Q: How do I set up MFA? 

You can set up MFA in your profile settings.

Expand or collapse content Q: Are there any exceptions to requiring MFA? 

Yes, if you log in via SSO and restrict login policy is enabled, we allow the administrator of the room to disable MFA so users don't need to verify MFA twice. 

The other exception is when MFA is paused for the user, which the room administrator can change at any time. 

For additional support or questions, please contact our support team at [email protected].

Previous Article Contract Works Release Notes - Q1 2025
Next Article Auto-Apply Tag Templates to Folders

© 2025 Onit, Inc.

docs.onit.com contains proprietary and confidential information owned by Onit, Inc. that is subject to copyright. Onit presents it exclusively to you for your sole use in conjunction with using Onit products. No portion of the materials contained herein may be used for any other purpose. No portion of the materials contained herein may be shared with third parties or reproduced in any form.