Problem
Admins cannot require teammates to use two-factor authentication, leaving account security dependent on individual compliance.
Request
Allow admins to enforce 2FA company-wide, blocking access for teammates who have not completed setup. This standardizes the security posture and enables compliance monitoring.
Considering that Front will have such broad access to customer contain details and customer information, this is a rather glaring information security risk gap. It poses a big reputational risk for Front if any of its customers' data were leaked due to this security flaw.
Some suggestions:
Allow admins to enforce sign in only via Google OAuth SSO (any plans).
Allow admins to enforce MFA (any plans).
Allow admins to configure SAML SSO (business/enterprise plans).
It is really important for us to be able to do this as it poses a major security risk. Digital fraud is on the rise right now. While our gmail is secured, front isnt, which links to gmail which removes the security much needed.