Skip to content
Find my data room
Data room terms / Security and compliance

Two-factor authentication (2FA)

The short version

A login that needs a second proof of identity besides the password, such as a code from an authenticator app, a text message or a hardware key.

How it plays out on a deal

Stolen or reused passwords are the most common way into business systems, and data rooms are no exception. A second factor blocks most of those attempts. For a room holding deal documents it should be a minimum, not an option.

The setting that matters is enforcement. Many platforms offer two-factor login but leave it to each user to switch on. Sellers should be able to require it for everyone in the room, or at least for every outside party, and choose which methods count.

What to check in a review or demo

  1. 1Whether administrators can require two-factor login for all users in a room.
  2. 2Which methods are accepted, and whether text message codes can be excluded.
  3. 3How a locked-out user regains access, and whether that path is logged.

Two-factor login: where the reviewed providers stand

From the twelve-item feature checklist in our reviews: a provider counts only if the feature ships natively. Read the review for how it works and on which plan.

Read alongside

Where this comes up on Data Room Review