How to Set Up 2-Step Verification (2FA) Enforcement in Google Workspace

The Necessity of 2-Step Verification

In the modern threat landscape, relying solely on passwords is a massive security vulnerability. Phishing attacks, password reuse, and brute-force credential stuffing mean that it is only a matter of time before an employee’s password is compromised. To protect your corporate data, Google Workspace administrators must mandate 2-Step Verification (2FA / MFA) across the entire organization, ensuring that even if a hacker steals a password, they cannot access the account without the user’s physical phone or hardware security key.

Step 1: Allow Users to Enroll

Before you can force everyone to use 2FA, you must first verify that your users actually have the permission to turn it on.

  1. Log into the Google Workspace Admin Console (admin.google.com).
  2. Navigate to Security > Authentication > 2-step verification.
  3. Select your root Organizational Unit (OU) on the left side of the screen.
  4. Ensure the box next to Allow users to turn on 2-Step Verification is checked. (If it wasn’t, check it and click Save).

Step 2: The Enrollment Period

You cannot simply turn on enforcement immediately. If you do, any employee who hasn’t set up their phone yet will be instantly locked out of their email and Google Drive, causing a massive flood of IT Helpdesk tickets.

You must give your organization a grace period to configure their settings.

  1. Send a company-wide email instructing all employees to navigate to myaccount.google.com/security and set up their 2-Step Verification methods (e.g., Google Prompt, SMS, or an Authenticator App).
  2. In the Admin Console (under the same 2-Step Verification menu), scroll down to the Enforcement section.
  3. Click the radio button for Turn on enforcement from date.
  4. Select a date two to four weeks in the future. Click Save.

During this enrollment period, users will see aggressive, unskippable prompts every time they log in, warning them of the impending deadline and forcing them to enroll a device.

Step 3: Total Enforcement

Once the deadline date passes, the system will automatically transition from “Turn on enforcement from date” to On.

From that moment forward, any user who failed to enroll a 2FA method will be completely locked out of their account. They will be greeted by an error message stating their organization requires 2-Step Verification. They will be forced to contact the IT department.

Handling Locked Out Users (Backup Codes)

If an employee is locked out because they ignored the warnings (or if they lost their mobile phone on a business trip), an administrator can generate temporary backup codes to get them back in.

  1. In the Admin Console, go to Directory > Users and click on the locked-out user.
  2. Scroll down to the Security section and expand it.
  3. Click on 2-Step Verification Backup Codes.
  4. Click Get Backup Codes.

You can read one of these 8-digit codes over the phone to the employee. They can enter it at the Google login screen instead of a text message, allowing them to bypass the 2FA prompt, log in, and register a new mobile device.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.