> **Source:** https://knowledge.leegality.com/document-execution/leegality-features/invitee-level/security/two-factor-authentication > **Site:** Leegality Knowledge Base — https://knowledge.leegality.com > **About:** Leegality is a document execution platform covering eSigning, stamps, NeSL, workflows, and REST API integration. > **Navigation:** Every article on this site has a plain-text version at `.txt` (this format). To get an index of all articles with their `.txt` links, read: https://knowledge.leegality.com/llms.txt > **AI Guide:** For instructions on how to navigate this knowledge base as an AI agent, read: https://knowledge.leegality.com/ai-readable.txt --- # Two Factor Authentication **Two Factor Authentication** enhances document security by requiring invitees to authenticate using OTPs sent to both their Email ID and Phone Number before accessing the document. This ensures an additional layer of protection, preventing unauthorized access even if the signing invitation is mistakenly forwarded. To enable this feature, both the Email ID and Phone Number must be configured during document creation. ## How Two Factor Authentication Works 1. **Signing Link Accessed via Email or Phone Number:** - **Via Invitee Email:** If the signing link is accessed through the invitee's email, this counts as one authentication. The invitee will only need to complete OTP authentication for their mobile number. - **Via Invitee Phone Number:** If the signing link is accessed through the invitee's phone number, this counts as one authentication. The invitee will only need to complete OTP authentication for their email. 2. **Signing Link Accessed via Other Sources:** - If the signing link is accessed through any other source, both OTP authentications will be required—one for the email and one for the phone number. ## Use Two Factor Authentication #### V3 Workflow 1. On the **Invitee card**, click **Invitee level Options**. 2. Toggle ON **Enable Security Features**. 3. Enable **Require '2-factor authentication' before document preview**. This will open up both email and phone fields for you to enter for the signatory. Entering both fields is mandatory in case of a 2FA flow. #### Workflow Creation 1. On the **Invitee card**, click **More options**. 2. Toggle ON **Advanced Security Features**. 3. Enable **Enforce 2-Factor Authentication before document preview**. This will open up both email and phone fields for the signatory. If you are **Configuring Invitee** during Workflow creation, then you need to enter both fields at this step. In case you want to allow the Workflow Runner to enter these fields, leave the **‘Configure Invitee’** toggle off. Do note that the Workflow Runner will have to mandatorily enter both of these fields. #### V4 Workflow 1. On the **Invite** stage, select the invitee card. 2. In the right panel, open the **Settings** tab and go to **Security Options**. 3. Enable **2 Factor Authentication before document preview** — the invitee must verify OTPs via both email and phone number before they can preview the document. #### Workflow Creation 1. On the **Invite** stage, select the invitee card. 2. In the right panel, open the **Settings** tab and go to **Security Options**. 3. Enable **2 Factor Authentication before document preview** — the invitee must verify OTPs via both email and phone number before they can preview the document. **Note:** Whether the workflow runner can modify this setting depends on the [field properties](https://knowledge.leegality.com/document-execution/workflows/v4/setup-configuration/field-properties) set by the workflow creator. > **Info — Note** > > 2-factor authentication doesn't work with Quick Sign > **Info — Note** > > Organisation Admins can enforce Two-Factor Authentication (2FA) for all documents sent from their accounts to enhance security. To learn how to enable this setting, [**click here**](https://knowledge.leegality.com/document-execution/settings/Department/document-security-settings)