How to Configure Security and Two-Factor Authentication in CrmLeaf
All editions. Core feature - no add-on required. Email and IP blacklists and login-expiry policies require the Cyber Security add-on module to be enabled for your account.
Availability: All editions. Core feature - no add-on required. Email and IP blacklists and login-expiry policies require the Cyber Security add-on module to be enabled for your account.
Overview
CrmLeaf groups access and security configuration into a set of settings areas: security, two-factor authentication, social login, signup and GDPR. Together they decide how people sign in to your account, how strongly they are authenticated, and how you handle consent.
Configure these before you invite your team, because sign-in behaviour is easier to set once than to change for everyone later.
How It Works
Security settings apply at account level. Two-factor authentication adds a second step at sign-in, using either a time-based one-time password from an authenticator app or a code sent by email. Social login lets users sign in with an existing Google or Microsoft identity instead of a password.
Security settings → Enable 2FA method → Users enrol → Social login configured → Signup and GDPR settings
- Two-factor authentication supports two methods: TOTP, using an authenticator application, and email, where a code is sent to the user's address.
- Social login supports Google and Microsoft. The same providers are available for signup, so a new account can be created with a social identity.
- Signup settings control how new accounts and users are admitted. An optional approval gate can hold a new account until it is approved.
- GDPR settings support consent handling. In the CRM, leads have public consent pages that an Administrator can approve or reject.
- The Cyber Security add-on module adds email and IP blacklists, login-expiry policies and its own security settings.
- Security configuration is separate from permissions. Security decides how someone signs in; permission scopes decide which records they then see.
Who Can Use This Feature?
Administrator
- Configure the account's security settings.
- Enable two-factor authentication and choose the method or methods offered.
- Configure Google and Microsoft social login.
- Configure signup and GDPR settings.
User
- Enrol in two-factor authentication on your profile and keep your authenticator application available.
- Sign in with a social identity where it has been configured.
- Change your own password.
Access depends on the modules and role assigned by your Administrator. Only Administrators can change the account's security configuration.
Prerequisites
- SMTP is configured and tested, because email-based two-factor codes and account emails depend on it.
- Credentials from Google or Microsoft, if you are enabling social login.
- An authenticator application on users' devices, if you are enabling TOTP.
Two-Factor Authentication Methods
| Method | How the user authenticates | Depends on |
|---|---|---|
| TOTP | A time-based one-time code from an authenticator application on their device. | The user having the authenticator application available at sign-in. |
| A code sent to the user's email address. | Working SMTP configuration and access to the mailbox. |
For Administrators
Step 1: Review security settings
What to do: Review the account's security options and Save your choices.
What to verify: Sign in as a test user and confirm the sign-in behaviour matches what you configured.
Step 2: Enable two-factor authentication
What to do: Enable two-factor authentication and choose whether TOTP, email, or both are offered, then Save. Confirm SMTP is working before you rely on the email method.
What to verify: A test user is prompted for a second factor at sign-in and can complete it.
Step 3: Configure social login
What to do: Enter the credentials for Google and Microsoft as required and Save.
What to verify: A test user can sign in with the social provider you configured.
Step 4: Configure signup settings
What to do: Review the signup options and Save.
What to verify: The signup behaviour matches your policy.
Step 5: Configure GDPR settings
What to do: Configure your consent handling and Save. In the CRM, consent requests are presented to leads on public pages, and an Administrator approves or rejects them.
What to verify: A consent request can be issued and actioned end to end.
For Users
Step 1: Enrol in two-factor authentication
What to do: Enrol in two-factor authentication using the method your Administrator has enabled. For TOTP, add CrmLeaf to your authenticator application. For the email method, confirm you can reach your mailbox.
What to verify: Sign out and sign back in. You are asked for the second factor and can complete it.
Step 2: Keep your second factor available
What to do: Keep the device with your authenticator application accessible, and keep your email address current. Tell your Administrator immediately if you lose access.
What to verify: You can sign in without help.
Expected Result
Your account's sign-in behaviour is configured, two-factor authentication is available by authenticator application or by email, users can sign in with Google or Microsoft where configured, and signup and consent handling follow your policy.
Important Notes
- Menu names and their position can differ between product editions and can be customised for your account, so your sidebar may not match these paths exactly. Use Search or your Quick Access items if you cannot find a screen.
- Configure and test SMTP before relying on email-based two-factor codes. Without working email, users cannot receive their code.
- Security controls sign-in. It does not control which records a user sees - that is the permission scope.
- Personal access tokens are a separate credential. Review and revoke them as part of any security review, and when someone leaves.
- Email and IP blacklists and login-expiry policies come from the Cyber Security add-on module. Confirm it is included in your plan before promising them.
- Security settings are held at Company level and apply across its Organizations.
Common Scenarios
Example: protecting a finance team. The Administrator enables two-factor authentication and asks the finance team to enrol with an authenticator application. Sign-in now requires the device as well as the password.
Example: fewer passwords to manage. A company already uses Microsoft accounts. The Administrator configures Microsoft social login, and staff sign in with their existing identity instead of a separate CrmLeaf password.
Example: someone leaves. The Administrator removes the user's access, reviews the account for personal access tokens issued by that user, and revokes them.
Troubleshooting
| Issue | Possible Cause | Resolution |
|---|---|---|
| A user does not receive their email two-factor code | SMTP is not configured or is not working | Configure SMTP and use its test until a message arrives. |
| A user has lost their authenticator device | The second factor is tied to that device | An Administrator must assist. |
| Social login is not offered at sign-in | Social login has not been configured for the account | Enter the provider credentials in social login settings. |
| A user signs in but cannot see records | This is a permission question, not a security one | Review the role's permission scope for that module. |
| A new account cannot sign in after signup | The optional approval gate is enabled and the account is pending | Approve the account, or contact the provider of your CrmLeaf instance. |
Frequently Asked Questions
Which two-factor methods does CrmLeaf support?
Two: TOTP using an authenticator application, and a code sent by email.
Which social login providers are supported?
Google and Microsoft, for both sign-in and signup.
Does two-factor authentication change what a user can see?
No. Security settings govern sign-in. Record visibility is governed by permission scopes.
Do personal access tokens require two-factor authentication?
A personal access token is a separate credential issued by the user and pinned to their Company and Organization. Review and revoke tokens as part of your security process.
Related Articles
Our support team answers on business days. Reference PLT-13 so we can jump straight in.