PLT-13Core CrmLeafAdministratorUser

How to Configure Security and Two-Factor Authentication in CrmLeaf

All editions. Core feature - no add-on required. Email and IP blacklists and login-expiry policies require the Cyber Security add-on module to be enabled for your account.

Availability: All editions. Core feature - no add-on required. Email and IP blacklists and login-expiry policies require the Cyber Security add-on module to be enabled for your account.

Overview

CrmLeaf groups access and security configuration into a set of settings areas: security, two-factor authentication, social login, signup and GDPR. Together they decide how people sign in to your account, how strongly they are authenticated, and how you handle consent.

Configure these before you invite your team, because sign-in behaviour is easier to set once than to change for everyone later.

How It Works

Security settings apply at account level. Two-factor authentication adds a second step at sign-in, using either a time-based one-time password from an authenticator app or a code sent by email. Social login lets users sign in with an existing Google or Microsoft identity instead of a password.

Security settings Enable 2FA method Users enrol Social login configured Signup and GDPR settings

  • Two-factor authentication supports two methods: TOTP, using an authenticator application, and email, where a code is sent to the user's address.
  • Social login supports Google and Microsoft. The same providers are available for signup, so a new account can be created with a social identity.
  • Signup settings control how new accounts and users are admitted. An optional approval gate can hold a new account until it is approved.
  • GDPR settings support consent handling. In the CRM, leads have public consent pages that an Administrator can approve or reject.
  • The Cyber Security add-on module adds email and IP blacklists, login-expiry policies and its own security settings.
  • Security configuration is separate from permissions. Security decides how someone signs in; permission scopes decide which records they then see.

Who Can Use This Feature?

Administrator

  • Configure the account's security settings.
  • Enable two-factor authentication and choose the method or methods offered.
  • Configure Google and Microsoft social login.
  • Configure signup and GDPR settings.

User

  • Enrol in two-factor authentication on your profile and keep your authenticator application available.
  • Sign in with a social identity where it has been configured.
  • Change your own password.

Access depends on the modules and role assigned by your Administrator. Only Administrators can change the account's security configuration.

Prerequisites

  • SMTP is configured and tested, because email-based two-factor codes and account emails depend on it.
  • Credentials from Google or Microsoft, if you are enabling social login.
  • An authenticator application on users' devices, if you are enabling TOTP.

Two-Factor Authentication Methods

MethodHow the user authenticatesDepends on
TOTPA time-based one-time code from an authenticator application on their device.The user having the authenticator application available at sign-in.
EmailA code sent to the user's email address.Working SMTP configuration and access to the mailbox.

For Administrators

Step 1: Review security settings

What to do: Review the account's security options and Save your choices.

What to verify: Sign in as a test user and confirm the sign-in behaviour matches what you configured.

Step 2: Enable two-factor authentication

What to do: Enable two-factor authentication and choose whether TOTP, email, or both are offered, then Save. Confirm SMTP is working before you rely on the email method.

What to verify: A test user is prompted for a second factor at sign-in and can complete it.

Step 3: Configure social login

What to do: Enter the credentials for Google and Microsoft as required and Save.

What to verify: A test user can sign in with the social provider you configured.

Step 4: Configure signup settings

What to do: Review the signup options and Save.

What to verify: The signup behaviour matches your policy.

Step 5: Configure GDPR settings

What to do: Configure your consent handling and Save. In the CRM, consent requests are presented to leads on public pages, and an Administrator approves or rejects them.

What to verify: A consent request can be issued and actioned end to end.

For Users

Step 1: Enrol in two-factor authentication

What to do: Enrol in two-factor authentication using the method your Administrator has enabled. For TOTP, add CrmLeaf to your authenticator application. For the email method, confirm you can reach your mailbox.

What to verify: Sign out and sign back in. You are asked for the second factor and can complete it.

Step 2: Keep your second factor available

What to do: Keep the device with your authenticator application accessible, and keep your email address current. Tell your Administrator immediately if you lose access.

What to verify: You can sign in without help.

Expected Result

Your account's sign-in behaviour is configured, two-factor authentication is available by authenticator application or by email, users can sign in with Google or Microsoft where configured, and signup and consent handling follow your policy.

Important Notes

  • Menu names and their position can differ between product editions and can be customised for your account, so your sidebar may not match these paths exactly. Use Search or your Quick Access items if you cannot find a screen.
  • Configure and test SMTP before relying on email-based two-factor codes. Without working email, users cannot receive their code.
  • Security controls sign-in. It does not control which records a user sees - that is the permission scope.
  • Personal access tokens are a separate credential. Review and revoke them as part of any security review, and when someone leaves.
  • Email and IP blacklists and login-expiry policies come from the Cyber Security add-on module. Confirm it is included in your plan before promising them.
  • Security settings are held at Company level and apply across its Organizations.

Common Scenarios

Example: protecting a finance team. The Administrator enables two-factor authentication and asks the finance team to enrol with an authenticator application. Sign-in now requires the device as well as the password.

Example: fewer passwords to manage. A company already uses Microsoft accounts. The Administrator configures Microsoft social login, and staff sign in with their existing identity instead of a separate CrmLeaf password.

Example: someone leaves. The Administrator removes the user's access, reviews the account for personal access tokens issued by that user, and revokes them.

Troubleshooting

IssuePossible CauseResolution
A user does not receive their email two-factor codeSMTP is not configured or is not workingConfigure SMTP and use its test until a message arrives.
A user has lost their authenticator deviceThe second factor is tied to that deviceAn Administrator must assist.
Social login is not offered at sign-inSocial login has not been configured for the accountEnter the provider credentials in social login settings.
A user signs in but cannot see recordsThis is a permission question, not a security oneReview the role's permission scope for that module.
A new account cannot sign in after signupThe optional approval gate is enabled and the account is pendingApprove the account, or contact the provider of your CrmLeaf instance.

Frequently Asked Questions

Which two-factor methods does CrmLeaf support?

Two: TOTP using an authenticator application, and a code sent by email.

Which social login providers are supported?

Google and Microsoft, for both sign-in and signup.

Does two-factor authentication change what a user can see?

No. Security settings govern sign-in. Record visibility is governed by permission scopes.

Do personal access tokens require two-factor authentication?

A personal access token is a separate credential issued by the user and pinned to their Company and Organization. Review and revoke tokens as part of your security process.

Still need a hand?

Our support team answers on business days. Reference PLT-13 so we can jump straight in.