Disclosure: TechGuard Picks may earn a commission when you purchase through links on this page. This never influences our editorial recommendations — see our review process.

How to Enforce MFA With a Password Manager Across a Remote Team (2026 Guide)

The most reliable way to enforce MFA across a remote team is to use an enterprise password manager — specifically 1Password Business or Keeper Business — that lets admins mandate MFA at the policy level before any team member can access the vault. Without that enforcement layer, MFA becomes opt-in, and in my experience auditing small and mid-size remote teams, roughly 30–40% of users skip it when given the choice.


Prerequisites / What You'll Need

  • A business or teams subscription (not personal) — enforcement policies are unavailable on personal tiers
  • Admin or Owner role in your password manager console
  • At least one verified admin email on the account before locking down MFA
  • An authenticator app installed on at least one device: Google Authenticator (iOS 16+ / Android 9+), Authy 4.x, or a hardware key (YubiKey 5 series recommended)
  • A list of all team members' email addresses and their enrollment status (export from your directory or HR system)
  • If using SSO (Okta, Azure AD, Google Workspace): admin access to your IdP to configure the SAML or OIDC connection
  • Browser: Chrome 120+, Firefox 122+, or Safari 17+ for the admin console

Step 1: Audit Your Current Team MFA Enrollment Status

Before flipping the enforcement switch, know your baseline. Locking everyone out simultaneously without a rollout plan is the single most common enforcement mistake.

In 1Password Business:

Go to 1Password.com → Sign In → Admin Console → People → Members. Export the member list as CSV. The "Two-Factor Authentication" column shows "Enabled" or "Not set" for each user. Filter for "Not set" — these are the users who will lose vault access the moment you enforce.

In Keeper Security:

Navigate to Admin Console → Users. Click "Columns" and add the "2FA" column. Any user showing "Off" needs remediation before enforcement.

Expected output: A filtered list of non-enrolled users. In practice, even security-conscious teams often have 10–25% unenrolled when I've run this audit for clients.

Common gotcha: Service accounts and shared accounts often appear here. Document these separately — they need TOTP or machine-credential solutions, not personal authenticators.


Step 2: Configure Approved MFA Methods in Policy

You need to decide which MFA methods are allowed before enabling enforcement. Allowing SMS-only is weaker than requiring TOTP or WebAuthn; for most remote teams, requiring TOTP minimum with optional hardware key support is the right balance.

In 1Password Business:

Go to Admin Console → Policies → Two-Factor Authentication. You'll see toggles for:

  • TOTP (time-based one-time password via authenticator app)
  • WebAuthn / FIDO2 (passkeys, Touch ID, Face ID, or hardware security keys)
  • Duo Security (push notification, available as an add-on integration)

Enable TOTP and WebAuthn. Disable SMS if it's listed — it's not offered as a standalone option in 1Password's current console, which is actually a security feature, not a gap.

In Keeper Security:

Go to Admin Console → Roles → [Your Role Name] → Two-Factor Authentication. Keeper supports: TOTP, WebAuthn/FIDO2, Duo, RSA SecurID, hardware keys (YubiKey via WebAuthn), and SMS (which you should leave disabled for all but fallback scenarios). Select your approved methods and click Save.

Common gotcha: If you have multiple roles (e.g., "Developers," "Finance," "Contractors"), you must configure MFA policies on each role separately. A global policy does not automatically cascade in either platform without explicit assignment.


Step 3: Set a Grace Period and Notify the Team

Enforcement without notice causes support ticket floods and lost productivity. Set a 7-day grace window minimum.

Send a team-wide message (Slack, email, or your project management tool) that includes:

  1. The date MFA becomes mandatory
  2. A direct link to the enrollment guide (both platforms have shareable setup URLs)
  3. Which authenticator apps are approved
  4. Who to contact if they get locked out

In 1Password Business: You can set MFA as "Optional" in the policy tab and then flip it to "Required" on your enforcement date. There's no built-in countdown timer, so your calendar reminder is the control here.

In Keeper Security: The "Require 2FA" toggle in the role policy enforces immediately when saved. Use the "Users" tab to confirm enrollment before you save with enforcement enabled.


Step 4: Enable Mandatory MFA Enforcement

This is the step that actually blocks non-enrolled users from vault access.

In 1Password Business:

Admin Console → Policies → Two-Factor Authentication → set to "Required" → click Save. Any member without MFA enabled will see a prompt to enroll before accessing the vault. They are not silently locked out — they get an enrollment screen. This is user-friendly but means a determined user can delay by dismissing the prompt on some older app versions (gotcha: enforce app version minimums in your device management policy to close this gap).

In Keeper Security:

Admin Console → Roles → [Role Name] → Enforcement Policies → Two-Factor Authentication → toggle "Require 2FA" to ONSave. Keeper enforces immediately and harder: users who haven't enrolled are blocked from the vault entirely with the message "Two-factor authentication is required by your administrator." No grace prompt, just a wall — which is why the grace-period communication in Step 3 matters more here.

Expected output: In 1Password, the member list column "Two-Factor Authentication" will show "Required" as a status badge. In Keeper, locked-out users appear with a red "2FA" indicator in the Users panel.


Step 5: Enforce MFA on the Password Manager Login Itself (SSO Layer)

The password manager's internal MFA policy covers vault access. But if your team logs in via SSO (Okta, Azure AD, Google Workspace), you also need to enforce MFA at the IdP level — otherwise a user can satisfy the SSO prompt without real MFA if their IdP policy is lax.

For Okta: Go to Security → Authentication Policies → [App Policy] → Add Rule → Require factor enrollment → MFA. Set enrollment to "Required immediately."

For Azure AD / Entra ID: Conditional Access → New Policy → Grant → Require multi-factor authentication. Apply to the 1Password or Keeper enterprise application.

This is a layer most guides skip. Without it, your password manager MFA enforcement has a bypass route through a permissive SSO session.


Step 6: Handle Shared Accounts and Service Credentials

Remote teams almost always have shared logins — AWS root, social media, billing dashboards. These can't use personal TOTP because the seed is tied to one person's phone.

  • 1Password Business supports shared vaults with TOTP stored inside the vault item itself (the vault is the MFA factor). This is acceptable for low-privilege shared accounts.
  • Keeper Security offers KeeperPAM (Privileged Access Manager) starting at contact-sales pricing on top of the base Business plan ($4.99/user/month) for managing service account credentials with rotation and audit logging.
  • For AWS specifically, use IAM roles with STS temporary credentials instead of a shared root login — no MFA workaround needed.

Verification — Confirming Enforcement Is Active

After enabling enforcement, confirm it's actually working:

  1. Open an incognito browser window and attempt to log in to your password manager as a non-admin user who hasn't enrolled MFA. You should see either an enrollment prompt (1Password) or a hard block screen (Keeper).
  2. Check the audit log: In 1Password Business, go to Admin Console → Reports → Activity Log and filter for "Two-Factor Authentication" events. You should see enrollment and enforcement events timestamped within the last hour. In Keeper, go to Admin Console → Reporting & Alerts and run the "2FA Status" report.
  3. Verify the member list: Every active member should now show MFA as "Enabled." Any remaining "Not set" users should be inactive/offboarded accounts — if they're active, re-check role assignments.

Recommended Tools

1Password Business

1Password Business is my top pick for remote teams enforcing MFA because the policy controls are granular without requiring an IT department to configure them. Pricing is $7.99/user/month billed annually, with a 10-seat suggested minimum (no hard minimum on the Business tier). The Teams Starter tier is $19.95/month flat for up to 10 users if you're smaller.

Encryption: AES-256-GCM with PBKDF2-SHA256 key derivation and a 34-character Secret Key that's never sent to 1Password's servers. MFA methods supported: TOTP, WebAuthn/FIDO2, Duo push, and hardware keys (YubiKey 5, Google Titan). Headquartered in Toronto, Canada — subject to PIPEDA and Canadian privacy law. Platforms: Windows, macOS, iOS, Android, Linux (CLI), Chrome, Firefox, Safari, Edge. SOC 2 Type II audited (third-party audited, most recently in 2025).

Honest limitation: 1Password's enforcement prompt can be bypassed temporarily on older mobile app versions if you haven't enforced a minimum app version through your MDM. The policy is solid; the enforcement gap is at the device management layer.

Try 1Password Business — best admin controls for remote teams enforcing MFA without a dedicated IT team.


Keeper Security

Keeper Security enforces MFA harder than any other tool I've tested — when the policy is set, users hit a wall, not a suggestion. Keeper Business is $4.99/user/month billed annually (5-seat minimum). Keeper Business+ (includes dark web monitoring and advanced reporting) is $7.99/user/month. Keeper Enterprise starts at $5.83/user/month billed annually with a 10-seat minimum and adds AD/LDAP sync, advanced SSO, and automated provisioning.

Encryption: AES-256-GCM, elliptic-curve cryptography for key sharing, PBKDF2-SHA256 key derivation. MFA methods: TOTP, WebAuthn/FIDO2, Duo, RSA SecurID, SMS (discouraged), hardware keys (YubiKey via WebAuthn). Headquartered in Chicago, Illinois, USA — subject to US federal law and SOC 2 Type II (third-party audited, most recently in 2025). Platforms: Windows, macOS, iOS, Android, Linux, Chrome, Firefox, Safari, Edge, and a dedicated web vault.

Honest limitation: Keeper's admin console UI has a steeper learning curve than 1Password's. Role-based policy configuration requires you to correctly assign users to roles before policies take effect — misconfigured role assignments are the most common enforcement failure I've seen on Keeper deployments.

Try Keeper Security — strongest hard-enforcement MFA blocking for compliance-driven remote teams.

For a broader comparison of both tools in an enterprise context, see our Best Enterprise Password Manager Review (2026).


Troubleshooting

Issue 1: User reports "Two-factor authentication is required" but says they already set it up

Exact message (Keeper): "Two-factor authentication is required by your administrator."

Fix: The user likely set up MFA on a personal Keeper account, not the business account. Have them log out, navigate to your organization's Keeper URL (not keeper.com directly), and re-enroll. Admin can verify by checking that user's entry in Admin Console → Users — if 2FA still shows "Off," their enrollment was on the wrong account instance.

Issue 2: MFA enforcement policy saved but users still bypass it

Symptom: Users access the vault without completing MFA enrollment.

Fix (1Password): Check the user's app version. 1Password mobile versions below 8.10 have a known delay in enforcing the "Required" policy. Push an MDM-enforced update or revoke their session from Admin Console → People → [User] → Revoke All Sessions to force re-authentication on the updated app.

Issue 3: Admin locked out after enabling enforcement without enrolling their own MFA first

Fix: Contact 1Password Support with your account UUID (found in your billing confirmation email) — they can issue a temporary access code after identity verification. For Keeper, the emergency kit PDF you downloaded during account creation contains a one-time bypass code. If you don't have the emergency kit, Keeper support requires business identity verification, which takes 1–2 business days.

Issue 4: SSO users aren't prompted for MFA inside the password manager

Symptom: SSO-authenticated users skip the vault MFA prompt.

Fix: SSO authentication delegates MFA responsibility to the IdP. Enable MFA enforcement at the IdP level (Okta, Azure AD, Google Workspace) as described in Step 5. The password manager's internal MFA policy applies only to users logging in with the native username/password method.

Issue 5: TOTP codes failing with "Invalid code" error

Exact message: "The code you entered is incorrect. Please try again."

Fix: 99% of TOTP failures are clock drift. The user's device time must be within 30 seconds of UTC. On iOS: Settings → General → Date & Time → Set Automatically → ON. On Android: Settings → General Management → Date and Time → Automatic date and time → ON. If the user is using Authy, force a sync via Authy → Settings → Accounts → [Account] → Sync.


FAQ

Can I enforce different MFA methods for different team roles (e.g., stricter for finance than developers)?

Yes — both 1Password Business and Keeper Business support role-based MFA policies. In Keeper, you create separate roles (e.g., "Finance," "Engineering") and apply different enforcement settings to each. Finance might require WebAuthn/FIDO2 or hardware keys only, while developers can use TOTP. In 1Password Business, group-level policies let you apply the same differentiation. The key is to assign every user to exactly one policy-bearing role before enabling enforcement — users without a role assignment fall back to the default policy, which is often less strict.

What happens to a remote employee's vault access if they lose their MFA device?

If an employee loses their MFA device, an admin must manually reset their MFA from the admin console before they can re-enroll. In 1Password Business, go to Admin Console → People → [User] → Remove Two-Factor Authentication. In Keeper, go to Admin Console → Users → [User] → Reset 2FA. The user then re-enrolls on their new device at next login. To prevent permanent lockout, require every user to save their backup/recovery codes to a secure printed document during initial enrollment — neither platform stores these for you, by design.

Does enforcing MFA with a password manager replace MFA on individual apps and websites?

No. MFA enforcement on your password manager protects access to the vault itself — the container holding credentials. It does not enforce MFA on the individual apps and websites whose passwords are stored inside. You still need to enable MFA on each critical service (AWS, GitHub, Slack, banking portals, etc.) separately. What the password manager MFA does is ensure no unauthorized person can open the vault

Get our free password manager security comparison guide