General Settings
Authentication
Enforce two-factor authentication and set the company's password policy.
Definition: The Authentication page covers how the members of your company prove their identity: two-factor authentication and the level of complexity required for local account passwords.
Feature video
No video is available at this time.
Who is this for?
- Administrators responsible for the account access policy.
- IT and security teams who need to align Leexi with their internal requirements.
Permissions and licenses
- Page restricted to people allowed to change company settings.
- The settings apply to the whole company, with no exception per team or per user.
How to use it

Open the page
Go to Settings > Company > Authentication.
Enforce two-factor authentication
The Two-factor authentication enforced for the whole company setting requires a second factor on every password login.
Two things to know before enabling it:
- You can no longer disable the option yourself once it is enabled: contact Leexi if you need to revert.
- For OAuth logins (Google, Microsoft) and SSO, the second factor is delegated to your identity provider: that is where it must be enforced.
If SSO login is already enforced for your company, this setting is greyed out — the identity provider then handles authentication end to end.
Set the password policy
The second block defines what a local password must contain:
- Minimum length (characters): between 8 and 64.
- At least one uppercase letter (ABC...)
- At least one number (123...)
- At least one special character (!#$...)
Each requirement applies as soon as it is saved, both when creating a password and when renewing one.
Complete with the neighbouring pages
Authentication only covers login. To go further:
- SSO / SCIM to delegate login and provisioning to your identity provider.
- Permissions to frame what members can change themselves.
- Roles and Access rules to frame what each person sees once logged in.
Going further
- Enforcing SSO makes the local password policy irrelevant for the accounts concerned.
- Two-factor authentication protects login, not call visibility: that is what access rules are for.
- A stricter password policy applies at the next password change; it does not force an immediate reset.
Frequently asked questions
Not from the interface. Contact Leexi at support@leexi.ai if you need it removed.
No. For OAuth and SSO, the second factor is handled by your identity provider.
Things to watch out for
- Enable two-factor authentication knowingly: the operation cannot be reversed without Leexi's help.
- A very high minimum length combined with every character requirement multiplies reset requests.
- Check that your administrators have a working second factor before enforcing it for everyone.