Two-factor authentication (2FA), explained
Two-factor authentication (2FA) adds a second check when you sign in. After the password, you prove who you are with something else: a code from an authenticator app, a code sent to your phone, or a security key. Someone who has stolen or guessed your password still cannot get in without that second factor.
For a CRM, 2FA matters because the account holds your customers' names, phone numbers and conversations, and one leaked password is the most common way such data is exposed. Multi-factor authentication (MFA) is the general term for using two or more factors; 2FA is the most common form of it. Losing a phone should not lock someone out for good, so keep recovery codes somewhere safe and know how an administrator resets a second factor.
Authenticator apps are generally stronger than codes sent by SMS, which can be intercepted or redirected. For a team, the setting that matters most is enforcement: an administrator should be able to require 2FA for everyone rather than leave it optional. In DigiPix Flow, multi-factor sign-in is available on every plan and can be enforced across the whole workspace.