Authentication
Authenticator 2FA is recommended for every member and administrator. An unenrolled account may explicitly continue after the short pre-auth step; once 2FA is enabled, every later sign-in requires RFC 6238 TOTP verification or one single-use recovery code and cannot skip the factor.