Authenticator sign-in and identity confirmations limit repeated code attempts and new code requests. A wrong code keeps the same confirmation active. Follow any displayed wait time before trying again. A confirmation lasts at most five minutes: use Start again after expiry, or Send a new code for email. If authenticator sign-in expires, go back and sign in again. Reopening the dialog or choosing another project does not remove the wait.
Deleting a project, organization, or your own account always asks you to confirm your identity. If you have an authenticator enrolled, use its code. Otherwise the dialog sends a code to your account email as it opens. Email fallback is for deletion; policy changes and required publish, unpublish, and rollback confirmations still need an authenticator. Account deletion also requires you to resolve any sole-owner blockers first.
Two-factor authentication (2FA) is optional for each person by default (Profile > Security). An organization owner can require it for the whole org. While that policy is on, publishing a page, rolling back to a previous revision, and taking a published page offline also ask for a fresh authenticator code.
Requiring 2FA for every member
- Only the owner can turn this on, from Organization settings (or when creating the organization), and only after entering a fresh authenticator code themselves when changing it in settings. Creating an org with the requirement on does not ask for a code; if you do not have 2FA yet, you will set it up right after create. The owner must already have 2FA enrolled before they can require it for others from Settings.
- Once on, a member without 2FA is sent straight to the enrollment screen on their next sign-in to that org. There is no "Skip for now": they must set up an authenticator app before continuing.
- This applies to new invitations, first login, and existing members' next session into that org.
- While you belong to an org that requires 2FA, you cannot turn it off for your account, even from a different org's settings. You would need to leave that org, or ask its owner to turn the policy off.
- One authenticator app covers every organization you belong to. If you already have 2FA on, joining or being required to join a stricter org changes nothing for you.
Publishing, rollback, and taking a page offline
- When org-required 2FA is on, Publish, Roll back to here, and Take page offline ask for a fresh 6-digit authenticator code, then Confirm (the code does not auto-submit). For Publish and Rollback that comes before the last-chance countdown. There is no separate toggle for that.
- Publish when merged (auto-publish after a GitHub/GitLab/Azure DevOps merge) never asks for a code.