New Feature Toggle Enforces 2FA Across All Employee Roles
A new account-level feature flag forces two-factor authentication on every Employee role, locking the 2FA Required field on individual Role records and the Two-Factor Authentication Roles page. SAML SSO and OIDC logins bypass the 2FA requirement.
What changed
A new feature flag, Require 2FA for All Employee Roles, is available at Setup > Company > Enable Features > Company subtab > Access section. When enabled, every role classified as an Employee role is forced to require two-factor authentication. This is an all-or-nothing toggle — there is no way to exempt individual Employee roles while the feature is active.
Behavioral details
- All users holding one or more Employee roles must enroll in 2FA.
- The Two-Factor Authentication Roles page (
Setup > Users/Roles > Two-Factor Authentication Roles) displays every Employee role as 2FA-required, and the checkbox is grayed out. The Duration of Trusted Device column remains editable. - On individual Role records, the Two-Factor Authentication Required field becomes read-only for Employee roles.
- If a user authenticates via SAML SSO or OpenID Connect (OIDC), those protocols take precedence and the 2FA requirement is bypassed entirely.
- Disabling the feature restores whatever per-role 2FA settings were previously configured on the Two-Factor Authentication Roles page.
Important caveat — SAML/OIDC bypass
Organizations relying on SAML or OIDC should understand that enabling this feature does not add an extra 2FA step for those login flows. If your IdP does not enforce MFA on its side, those users will effectively have no second factor despite the feature being enabled. Verify your IdP MFA policy independently.
Scripting and integration impact
Oracle's documentation does not specify whether the Two-Factor Authentication Required field on the Role record (record.Type.ROLE) becomes read-only to SuiteScript when the feature is enabled, or whether attempts to set it via N/record will throw an error versus silently no-op. If you have scripts or integrations (e.g., SDF-managed role objects, CSV imports, or REST/SOAP calls) that programmatically set 2FA requirements on Employee roles, test them in Sandbox with the feature enabled before deploying to production.
Fields to watch:
is2aborforced(internal ID — verify in your account; the exact field ID is not documented in this source)- Any SDF
customroleobject that sets 2FA attributes
What to do
- Audit your current 2FA posture. Go to
Setup > Users/Roles > Two-Factor Authentication Rolesand note which Employee roles already require 2FA. Enabling the feature will override these settings; disabling it will restore them. - Communicate to users. Any employee-role user who has not enrolled in 2FA will be forced to set it up on next login. Coordinate a rollout window to minimize support tickets.
- Check your IdP configuration. If you use SAML SSO or OIDC, confirm your identity provider enforces MFA at its layer, since NetSuite's 2FA requirement is ignored for those flows.
- Enable the feature. Navigate to
Setup > Company > Enable Features > Company subtab > Access, check Require 2FA for All Employee Roles, and click Save. - Review automation. Search your SuiteScript customizations, SDF projects, and integration endpoints for any logic that reads or writes 2FA settings on Role records. Test in Sandbox to confirm they behave correctly with the feature active.
- Set trusted-device durations. Even with the feature enabled, the Duration of Trusted Device column remains editable per role. Adjust these values to balance security and user convenience.
Rollback
The feature can be disabled at any time via the same Enable Features page. Disabling it restores the previous per-role 2FA configuration. Oracle warns this significantly reduces account security — if you disable it, ensure you have adequate per-role 2FA settings in place.
Source: Oracle NetSuite Release Notes