Two-factor authentication is a level of account security for users during authorization. When attempting to log in, the user is sent a one-time login link.
Two-factor authentication can be enabled or disabled individually in each user's profile. This means one user might have it enabled while another doesn't.
By default, two-factor authentication is disabled for users on the front end. To enable it, go to the "Settings" section and enable "Authorization confirmation for users."
Regardless of whether a two-factor authentication message has been received, entering the confirmation is mandatory.
If you don't set a two-factor authentication message template, the message will be sent using the preset template. The message is configured in the "Messages" - "Two-Factor Authentication" section.