What you’ll need:
For setting up mandatory two-step verification: Admin access.
Keep in mind:
You can use email or an authenticator app for two-step verification.
You can use only one two-step verification method at a time.
Some sensitive actions require two-step verification to be enabled.
Kommo uses two-step verification to protect sensitive actions, such as launching broadcasts, changing Admin rights, deleting or exporting data in bulk, and creating custom integrations. Depending on the action, you may need to enable two-step verification or confirm your identity with a verification code.
Admins can also make two-step verification mandatory for all users. This adds an extra layer of protection across the entire workspace.
This article explains which actions Kommo protects with extra verification and how Admins can make two-step verification mandatory for all users.
If you need to enable two-step verification or change your verification method, see Set up two-step verification in Kommo.
Sensitive actions that require extra verification
The table below shows which actions are protected and what you need to complete them:
Feature | Actions that require two-step verification | What you need |
|---|---|---|
Password | If two-step verification is enabled, verify the action using your active method — email or an authenticator app. If it’s disabled, Kommo sends a verification code to the email linked to your account. | |
Email address | To change your email address, you'll need to verify both your current and new email addresses — regardless of your two-step verification method. Enter the code sent to your current email first, then the code sent to your new email. | |
Broadcasts | Launch a broadcast; change the send time of a scheduled broadcast | Two-step verification must be enabled. Verify the action using your active method — email or an authenticator app. |
User management | Add or delete a user; add a new user with Admin rights; give Admin rights to an existing user; change an Admin to a regular user | If two-step verification is enabled, verify the action using your active method — email or an authenticator app. If it’s disabled, Kommo sends a verification code to the email linked to your account. In the Kommo mobile app, two-step verification is required only when adding or deleting a user. |
Bulk deletion and export | Delete multiple leads, contacts, or companies at once; export leads, contacts, or companies in bulk | Two-step verification must be enabled. If it’s disabled, you can’t complete these actions. |
Integrations | Create a custom integration (for example, via n8n) | If two-step verification is enabled, verify the action using your active method — email or an authenticator app. If it’s disabled, Kommo sends a verification code to the email linked to your account. |
Note: Verification for granting Admin rights and bulk deletion or export is required on paid accounts only. If you're on a trial, you won't be asked to verify these actions — but you'll still need to verify password changes, broadcasts, and creating integrations.
Set up mandatory two-step verification
Admins can require all users in the workspace to enable two-step verification.
Each user can choose whether to use email or an authenticator app to meet this requirement.
Require two-step verification
Go to Settings → Workspace settings.
Scroll to Mandatory two-step verification.
Turn on the Mandatory two-step verification toggle.

Note: If two-step verification isn’t enabled for your account, you must enable it first before you can require it for other users.
Choose a compliance period from 1–10 days.
Verify your identity using your active two-step verification method:
Email: Click Send code, then enter the code sent to the email address linked to your profile.
Authenticator app: Enter the current code from your authenticator app.
Click Confirm.

Once enabled:
Users receive an email telling them that two-step verification is required and must be set up within the compliance period.
Users can choose email or an authenticator app as their verification method.
After the compliance period ends, users who haven’t enabled two-step verification must set it up the next time they log in.
Turn off mandatory two-step verification
Go to Settings → Workspace settings.
Scroll to Mandatory two-step verification.
Turn off the Mandatory two-step verification toggle.

Verify your identity using your active two-step verification method:
Email: Click Send code, then enter the code sent to the email address linked to your profile.
Authenticator app: Enter the current code from your authenticator app.
Click Confirm.

After you turn it off, users who don’t have two-step verification enabled can log in without setting it up.