How to Configure Security and Two-Factor Authentication in CrmLeaf
All editions. Core feature — no add-on required. Email and IP blacklists and login-expiry policies require the Cyber Security add-on module to be enabled for your account.
Availability: All editions. Core feature — no add-on required. Email and IP blacklists and login-expiry policies require the Cyber Security add-on module to be enabled for your account.
Overview
CrmLeaf groups access and security configuration into a set of settings areas: security, two-factor authentication, social login, signup and GDPR. Together they decide how people sign in to your account, how strongly they are authenticated, and how you handle consent.
Configure these before you invite your team, because sign-in behaviour is easier to set once than to change for everyone later.
How It Works
Security settings apply at account level, but two-factor authentication itself is personal and self-service: there is no account-wide switch that turns it on for everyone. Each user, including an Administrator, opens their own Settings → Security Settings screen and enables a second sign-in step for their own login, using either a time-based one-time code from an authenticator app or a code sent by email. Social login lets users sign in with an existing Google or Microsoft identity instead of a password.
Security Settings screen → Each user enables their own 2FA method → Social login configured → Signup and GDPR settings
- Two-factor authentication supports two methods: a code from an authenticator application (Google Authenticator or compatible), and a code sent by email. A user can enable one or both for their own login. Enabling an authenticator produces a QR code to scan and a set of downloadable/regeneratable recovery codes.
- There is no account-wide 2FA policy toggle. The Security Settings screen shows the current signed-in user's own two-factor status and lets that user turn their own second factor on or off. An Administrator cannot flip a single switch to require 2FA for the whole team; each teammate enables it for themselves.
- Social login supports Google and Microsoft. The same providers are available for signup, so a new account can be created with a social identity.
- Signup settings control how new accounts and users are admitted. An optional approval gate can hold a new account until it is approved.
- GDPR settings support consent handling. In the CRM, leads have public consent pages that an Administrator can approve or reject.
- The Cyber Security add-on module adds email and IP blacklists, login-expiry policies and its own security settings.
- Security configuration is separate from permissions. Security decides how someone signs in; permission scopes decide which records they then see.
Who Can Use This Feature?
Administrator
- Configure Google and Microsoft social login.
- Configure signup and GDPR settings.
- Enable and manage two-factor authentication for your own login — the same self-service option every user has (see User, below). You cannot enable it on a teammate's behalf.
User
- Enable and manage your own two-factor authentication (email code, authenticator app, or both) from Settings → Security Settings. No Administrator action is required.
- Sign in with a social identity where it has been configured.
- Change your own password.
Access depends on the modules and role assigned by your Administrator. Social login, signup and GDPR configuration are Administrator-only; two-factor authentication enrollment is available to every user, including Administrators, for their own account.
Prerequisites
- SMTP is configured and tested, because email-based two-factor codes and account emails depend on it.
- Credentials from Google or Microsoft, if you are enabling social login.
- An authenticator application on users' devices, if you are enabling TOTP.
Two-Factor Authentication Methods
| Method | How the user authenticates | Depends on |
|---|---|---|
| TOTP | A time-based one-time code from an authenticator application on their device. | The user having the authenticator application available at sign-in. |
| A code sent to the user's email address. | Working SMTP configuration and access to the mailbox. |
For Administrators
Step 1: Review the Security Settings screen
What to do: This single screen holds two tabs. Two-Factor Authentication is the default tab and is visible to every user — it shows and controls your own second-factor status only (see Step 2). A second tab, reCAPTCHA, is configured by CrmLeaf at the platform level and is not shown to a company Administrator.
What to verify: You see the Two-Factor Authentication tab; there is no separate reCAPTCHA tab on your screen.
Step 2: Enrol your own account in two-factor authentication
What to do: There is no account-wide setting to turn on here — enable your own second factor the same way any user does (see For Users, Step 1, below). Confirm SMTP is verified before you or your team rely on the email method. If you want the whole team using 2FA, ask each person to enrol themselves; there is no bulk or forced-enrollment option.
What to verify: Your own account is prompted for a second factor at your next sign-in after you enable it. A teammate can enrol on their own account without any action from you.
Step 3: Configure social login
What to do: Enter the credentials for Google and Microsoft as required and Save.
What to verify: A test user can sign in with the social provider you configured.
Step 4: Configure signup settings
What to do: Review the signup options and Save.
What to verify: The signup behaviour matches your policy.
Step 5: Configure GDPR settings
What to do: Configure your consent handling and Save. In the CRM, consent requests are presented to leads on public pages, and an Administrator approves or rejects them.
What to verify: A consent request can be issued and actioned end to end.
For Users
Step 1: Enrol in two-factor authentication
What to do: Choose either or both methods, on your own — no Administrator action is needed first. For Email, click Enable (this option only appears once SMTP is verified for your account); a code will be sent to your email address at sign-in. For Google Authenticator, click Enable, scan the QR code with your authenticator app, then enter the code it shows to validate the setup. Once validated, download or regenerate your recovery codes and store them somewhere safe — they are how you get back in if you lose the device.
What to verify: Sign out and sign back in. You are asked for the second factor and can complete it.
Step 2: Keep your second factor available
What to do: Keep the device with your authenticator application accessible, and keep your email address current. Tell your Administrator immediately if you lose access.
What to verify: You can sign in without help.
Expected Result
Your account's sign-in behaviour is configured, two-factor authentication is available by authenticator application or by email, users can sign in with Google or Microsoft where configured, and signup and consent handling follow your policy.
Important Notes
- Menu names and their position can differ between product editions and can be customised for your account, so your sidebar may not match these paths exactly. Use Search or your Quick Access items if you cannot find a screen.
- Configure and test SMTP before relying on email-based two-factor codes. Without working email, users cannot receive their code.
- Security controls sign-in. It does not control which records a user sees — that is the permission scope.
- Personal access tokens are a separate credential. Review and revoke them as part of any security review, and when someone leaves.
- Email and IP blacklists and login-expiry policies come from the Cyber Security add-on module. Confirm it is included in your plan before promising them.
- Security settings are held at Company level and apply across its Organizations — but two-factor authentication is the exception: enrollment is personal to each user's own login and is not something an Administrator sets for the Company.
- Two-factor authentication is opt-in and self-service for every user, including Administrators. There is no account-wide policy switch found in the product that forces it on for all users.
Common Scenarios
Example: protecting a finance team. The Administrator asks the finance team to enrol in two-factor authentication with an authenticator application. There is no switch the Administrator can flip on the team's behalf, so each team member goes to their own Settings → Security Settings screen and enables it for their own login. Sign-in now requires the device as well as the password for everyone who enrolled.
Example: fewer passwords to manage. A company already uses Microsoft accounts. The Administrator configures Microsoft social login, and staff sign in with their existing identity instead of a separate CrmLeaf password.
Example: someone leaves. The Administrator removes the user's access, reviews the account for personal access tokens issued by that user, and revokes them.
Troubleshooting
| Issue | Possible Cause | Resolution |
|---|---|---|
| A user does not receive their email two-factor code | SMTP is not configured or is not working | Configure SMTP and use its test until a message arrives. |
| A user has lost their authenticator device | The second factor is tied to that device | If they downloaded or regenerated recovery codes when they enabled the authenticator, they can use one of those codes to sign in and then disable or re-enrol the method. |
| Social login is not offered at sign-in | Social login has not been configured for the account | Enter the provider credentials in social login settings. |
| A user signs in but cannot see records | This is a permission question, not a security one | Review the role's permission scope for that module. |
| A new account cannot sign in after signup | The optional approval gate is enabled and the account is pending | Approve the account, or contact the provider of your CrmLeaf instance. |
Frequently Asked Questions
Which two-factor methods does CrmLeaf support?
Two: a code from an authenticator application (such as Google Authenticator), and a code sent by email. A user can enable one or both for their own login.
Does an Administrator turn on two-factor authentication for the whole team?
No. Two-factor authentication is opt-in and self-service: every user, including Administrators, enables it for their own account from Settings → Security Settings. There is no account-wide toggle that turns it on for everyone at once.
Which social login providers are supported?
Google and Microsoft, for both sign-in and signup.
Does two-factor authentication change what a user can see?
No. Security settings govern sign-in. Record visibility is governed by permission scopes.
Do personal access tokens require two-factor authentication?
A personal access token is a separate credential issued by the user and pinned to their Company and Organization. Review and revoke tokens as part of your security process.
Related Articles
Our support team answers on business days. Reference PLT-13 so we can jump straight in.