Manage security with two-step verification in Kommo

Prev Next

What you’ll need:

  • For setting up mandatory two-step verification: Admin access.

Keep in mind:

  • You can use email or an authenticator app for two-step verification.

  • You can use only one two-step verification method at a time.

  • Some sensitive actions require two-step verification to be enabled.

Kommo uses two-step verification to protect sensitive actions, such as launching broadcasts, changing Admin rights, deleting or exporting data in bulk, and creating custom integrations. Depending on the action, you may need to enable two-step verification or confirm your identity with a verification code.

Admins can also make two-step verification mandatory for all users. This adds an extra layer of protection across the entire workspace.

This article explains which actions Kommo protects with extra verification and how Admins can make two-step verification mandatory for all users.

If you need to enable two-step verification or change your verification method, see Set up two-step verification in Kommo.

Sensitive actions that require extra verification

The table below shows which actions are protected and what you need to complete them:

Feature

Actions that require two-step verification

What you need

Password

Change your password

If two-step verification is enabled, verify the action using your active method — email or an authenticator app. If it’s disabled, Kommo sends a verification code to the email linked to your account.

Email address

Change the email address linked to your profile

To change your email address, you'll need to verify both your current and new email addresses — regardless of your two-step verification method. Enter the code sent to your current email first, then the code sent to your new email.

Broadcasts

Launch a broadcast; change the send time of a scheduled broadcast

Two-step verification must be enabled. Verify the action using your active method — email or an authenticator app.

User management

Add or delete a user; add a new user with Admin rights; give Admin rights to an existing user; change an Admin to a regular user

If two-step verification is enabled, verify the action using your active method — email or an authenticator app. If it’s disabled, Kommo sends a verification code to the email linked to your account.

In the Kommo mobile app, two-step verification is required only when adding or deleting a user.

Bulk deletion and export

Delete multiple leads, contacts, or companies at once; export leads, contacts, or companies in bulk

Two-step verification must be enabled. If it’s disabled, you can’t complete these actions.

Integrations

Create a custom integration (for example, via n8n)

If two-step verification is enabled, verify the action using your active method — email or an authenticator app. If it’s disabled, Kommo sends a verification code to the email linked to your account.

Note: Verification for granting Admin rights and bulk deletion or export is required on paid accounts only. If you're on a trial, you won't be asked to verify these actions — but you'll still need to verify password changes, broadcasts, and creating integrations.

Set up mandatory two-step verification

Admins can require all users in the workspace to enable two-step verification.

Each user can choose whether to use email or an authenticator app to meet this requirement.

Require two-step verification

  1. Go to Settings → Workspace settings.

  2. Scroll to Mandatory two-step verification.

  3. Turn on the Mandatory two-step verification toggle. Workspace settings with the Mandatory two-step verification toggle turned off.

Note: If two-step verification isn’t enabled for your account, you must enable it first before you can require it for other users.

  1. Choose a compliance period from 1–10 days.

  2. Verify your identity using your active two-step verification method:

  • Email: Click Send code, then enter the code sent to the email address linked to your profile.

  • Authenticator app: Enter the current code from your authenticator app.

  1. Click ConfirmMandatory two-step verification setup window with a compliance period, email code, and Confirm button.

Once enabled:

  • Users receive an email telling them that two-step verification is required and must be set up within the compliance period.

  • Users can choose email or an authenticator app as their verification method.

  • After the compliance period ends, users who haven’t enabled two-step verification must set it up the next time they log in.

Turn off mandatory two-step verification

  1. Go to Settings → Workspace settings.

  2. Scroll to Mandatory two-step verification.

  3. Turn off the Mandatory two-step verification toggle. Workspace settings with the Mandatory two-step verification toggle turned on.

  4. Verify your identity using your active two-step verification method:

  • Email: Click Send code, then enter the code sent to the email address linked to your profile.

  • Authenticator app: Enter the current code from your authenticator app.

  1. Click ConfirmDisable mandatory two-step verification window with an email code and Confirm button.

After you turn it off, users who don’t have two-step verification enabled can log in without setting it up.