---
id: KB-AD-002
url: https://app.codecontract.io/help/administration/protecting-your-team-accounts
idioma: en
categoria: administracion
audiencia: administrador
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-AD-001, KB-AD-003]
citadoPor: [KB-AD-004, KB-PR-004, KB-ET-008, KB-AD-005, KB-AD-006, KB-AD-007, KB-AD-008, KB-AD-009, KB-AD-010, KB-AD-015, KB-AD-018, KB-ET-011, KB-AD-003, KB-ET-005, KB-IN-003]
enLaApp: https://app.codecontract.io/settings/security
---

# Protecting your team's accounts

_The three measures that prevent nearly everything, ordered by effort._

**Responde a:** enable two-factor authentication · require 2fa for the whole team · how do i protect my company account · someone accessed an account

What sits inside are contracts, payroll and identity documents belonging to people who are not here to protect them. Three measures cover almost everything that can go wrong, and all three take one afternoon.

## 1. Two-factor, mandatory

A password on its own leaks: it gets reused, written down, stolen from another service. A second factor means a stolen password is not enough. By some distance it is the best protection per unit of effort.

> [!IMPORTANT]
> Make it mandatory for the whole organisation, not optional. Optional means three people turn it on and the other twenty do not.

## 2. Each person with their own

Making everyone an administrator is convenient until the day someone deletes something. Those who only look, look; those who only sign, sign.

## 3. Watch who signs in

The log shows who signed in, from where and what they did. Reviewing it monthly catches the account of someone who left six months ago and is still open.

| Measure | Effort | Prevents |
| --- | --- | --- |
| Mandatory two-factor | One afternoon | A leaked password opening the door |
| Tight permissions | Half an hour | Accidental deletions and changes |
| Monthly review | Ten minutes a month | Live accounts for people who left |

> [!WARNING]
> When someone leaves, remove their access that same day. It is not distrust: it is that their account stays open and nobody is watching it any more.

**What if someone loses their two-factor phone?**

An administrator restores access after checking who they are. Which is why you want two administrators.

**Can people sign in with their work account?**

Yes, if you have corporate sign-in. It is the easiest option once you are many.

**Am I warned about odd sign-ins?**

Sign-ins are logged with their location and device.

## Ejemplos

**A sixty-person company makes two-factor mandatory.**

- Warns everyone a week ahead
- Switches it on a Monday
- Keeps two administrators able to restore access

→ Four people need help on day one and none after that.

**Somebody uses the same password as elsewhere.**

- Turns on the second factor for everyone

→ A leaked password stops being enough.

**The second factor is switched on unannounced and everyone locks out.**

- Gives a week's notice and leaves a recovery route

→ The change happens without stopping work.

**Nobody knows who has the second factor active.**

- Checks the status per person

→ The gaps become visible.

**Somebody loses a phone with the session open.**

- Closes their sessions from administration

→ Access is cut within minutes.

**An account is shared to get past a problem.**

- Creates that person their own account

→ The log keeps saying who did what.
