2FA is an important security feature to minimise that chance of an account being logged into by someone other than the authorised user. When the user attempts to log in, they will be sent a 6 digit code via email or SMS and will need to enter this within 10 minutes to log in.
If the code is entered incorrectly five times, the user will be blocked from logging in for 15 minutes.
Activate 2FA
Go to Admin>Staff>Security and check the boxes to enable 2FA via email and/or SMS.

