Bitrix24 Helpdesk

Reasons to enable two-factor authentication in Bitrix24

Two-factor authentication adds a second step to your sign-in. It helps protect company data if someone steals, guesses, or captures a password on a fake page. A username and password alone are not enough to access the account.

In Bitrix24, two-factor authentication is one of several security measures. Others include encrypted connections, file protection, and proactive security.
Restrict access to Bitrix24 by IP address


Why a password alone is not enough

Even a strong password cannot fully protect an account. Attackers use brute-force attacks, credential stuffing, and social engineering. Here are three common cases.

Phishing and social engineering. A user gets an email or message with a link to a page that looks like a trusted corporate service. The user enters their username and password, and the attacker captures them.
Phishing: How to protect your company
FAQ: Phishing

Password reuse. If someone uses the same username and password for several services, attackers can test stolen credentials on other websites, including a work account.

Malware. An infostealerAn infostealer is malware that collects data from a device and sends it to an attacker. can steal passwords saved in a browser, session data, and other identifiers.

In all of these cases, the issue is not always password strength. If someone else learns the password, one verification step is no longer enough.


How a second factor protects your account

With a standard sign-in, the correct username and password are enough. If an attacker gets these credentials, they can try to sign in as the employee.

When two-factor authentication is on, sign-in includes two steps:

  1. The user enters their username and password.
  2. Bitrix24 asks for confirmation in the mobile app, by SMS, or by email.

Without this second confirmation, the account stays protected. For example, if an employee enters their password on a fake page, the attacker can try to sign in. Bitrix24 then sends a request to the employee's trusted device. If the employee does not approve it, the sign-in fails.
New two-factor authentication in Bitrix24
FAQ: Security

Two-factor authentication helps protect accounts from phishing, brute-force attacks, and credential stuffing. A password alone is no longer enough to sign in.

Two-factor authentication does not guarantee complete protection. Never share one-time codes or backup codes with anyone. Only approve a sign-in if you started it yourself. If you get a request you did not expect, do not approve it.
Go to Bitrix24
Don't have an account? Create for free