How to roll out two-factor authentication for team email
A runbook for enabling 2FA across a team's email accounts: announcing it, choosing apps, storing recovery codes, handling lost phones and verifying everyone.

On this page(11 sections)
- Step 1: Decide the scope and the deadline
- Step 2: Announce it clearly
- Step 3: Help people choose an authenticator app
- Step 4: Get recovery codes stored properly
- Step 5: Run help sessions
- Step 6: Plan for lost phones before it happens
- Step 7: Track enrollment
- Step 8: Enforce
- Step 9: Keep it working
- Runbook checklist
- Key takeaways
Email accounts are the master key to almost everything else: password resets for every other tool land there. A password alone is a thin lock on that door, and two-factor authentication (2FA) is the simplest way to add a second one.
Turning it on for yourself takes two minutes. Getting a whole team enrolled, without lockouts or a week of "I can't log in" messages, takes a little planning. This runbook walks through it step by step for a small team.
Step 1: Decide the scope and the deadline
Before announcing anything, decide:
- Who: Every account that can access team email, including founders, contractors and anyone with access to shared mailboxes. Shared access through a personal account is only as strong as the weakest personal account.
- Which method: Authenticator apps (time-based codes) are a good default. They work offline and aren't tied to a phone number. Hardware security keys are stronger, if your email platform supports them and your team is willing. SMS codes are better than nothing but weaker, because phone numbers can be hijacked.
- The deadline: Two weeks is usually enough. Shorter and people miss it; longer and they forget.
- Enforcement: Will accounts without 2FA be blocked after the deadline? Decide now, and say so in the announcement.
Step 2: Announce it clearly
People resist security changes mostly because they don't know why, or fear getting locked out. Address both. A short announcement:
Subject: 2FA for team email – please enroll by [date]
Hi all,
We're turning on two-factor authentication for everyone with access to
team email, starting today. Email is where every other password reset
goes, so protecting it protects everything else.
What you need to do (about 5 minutes):
1. Install an authenticator app on your phone, if you don't have one.
2. Go to [account security settings] and turn on 2FA.
3. Save your recovery codes somewhere safe (see below).
Deadline: [date]. After that, sign-in will require 2FA.
Help sessions: [two time slots]. Or message [name] any time.
Recovery codes: store them in our password manager under your name,
not in your email or a note on your phone.
Thanks!
Step 3: Help people choose an authenticator app
Keep it simple. Point people to a reputable authenticator app available on both major phone platforms, or to the one built into your password manager if your team uses one. Mention two things:
- Backups matter. Some apps can back up or sync codes so a new phone doesn't mean losing access. Explain whether the app you recommend does this, and how to enable it.
- Don't use the same phone for everything without a plan. If the phone holds the authenticator, the password manager and the recovery codes, losing it is painful. Recovery codes stored elsewhere solve this.
Step 4: Get recovery codes stored properly
Recovery codes are one-time backup codes shown when 2FA is turned on. They're how someone gets back in when their phone is lost. They're also the most common thing people skip.
Set a clear rule for where they go:
| Good places | Bad places |
|---|---|
| Team password manager, in a personal vault entry | In the same email account they protect |
| Printed and kept somewhere physically secure | A screenshot in the phone's photo library |
| An encrypted personal password manager | A shared doc everyone can read |
Ask people to confirm they've stored their codes when they confirm enrollment.
Step 5: Run help sessions
Two short drop-in sessions during the enrollment window catch most problems. Typical issues:
- Codes rejected because the phone's clock is wrong (fix: enable automatic time)
- Scanning the setup QR code on the same phone that displays it (fix: open settings on a laptop)
- Confusion between the account password and the 2FA code
- Older phones that can't install the recommended app
Fifteen minutes with a screen share usually solves any of these.
Step 6: Plan for lost phones before it happens
Someone will lose or replace a phone. Decide the procedure in advance:
- They use a recovery code to sign in, then re-enroll 2FA on the new phone and generate fresh codes.
- If they have no recovery codes, an admin resets their 2FA after verifying identity. Verify through a channel other than email, such as a video call or in person, because the email account is what's being recovered.
- Log the reset, including who verified the person and how.
The identity check in step 2 matters. "I lost my phone, please reset my 2FA" is a classic social-engineering request. An admin should never reset 2FA based only on an email or chat message.
Step 7: Track enrollment
Keep a simple list:
Name Enrolled Method Recovery codes stored
Ana Yes App Yes
Ben Yes App Yes
Chen No – – ← follow up
Contractor D Yes Security key Yes
Many email platforms show 2FA status in an admin view, which is more reliable than self-reporting. Use it if you have it.
A few days before the deadline, message anyone not yet enrolled individually. Public reminders are easy to ignore; a direct message isn't.
Step 8: Enforce
On the deadline, turn on enforcement if your platform supports it. Anyone who hasn't enrolled will be prompted to do so at next sign-in. Have someone available that day to help.
If you use Koltrix, 2FA is available on accounts, so the same plan applies: each person enables it on their own account, which in turn protects the shared mailboxes they have access to.
Step 9: Keep it working
2FA isn't a one-time project. Fold it into existing processes:
- Onboarding: 2FA setup is part of day one, before access to shared mailboxes is granted.
- Offboarding: Remove access promptly; 2FA doesn't help if a departed person's account is still active.
- Annual check: Confirm everyone is still enrolled and recovery codes are current.
Runbook checklist
- Scope, method, deadline and enforcement decided
- Announcement sent with steps, deadline and help options
- Recommended authenticator app named, backup explained
- Recovery code storage rule set
- Two help sessions held
- Lost-phone procedure written, including identity verification
- Enrollment tracked; stragglers messaged individually
- Enforcement turned on at the deadline
- 2FA added to onboarding and offboarding checklists
Key takeaways
- Email protects every other account, so 2FA on email has outsized value.
- Authenticator apps are a solid default; avoid relying on SMS where you can.
- Recovery codes are the step people skip, so make storage explicit.
- Decide the lost-phone procedure in advance and never reset 2FA on an unverified request.
- Track enrollment, enforce on a deadline, and build 2FA into onboarding.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


