The short answer
Yes. HighLevel logins can be protected with a one-time code sent by email or SMS, or with any TOTP authenticator app such as Google Authenticator, Microsoft Authenticator or Authy. Portal administrators can require two-factor authentication for every user, the mobile app supports it, and changing the phone number on a profile always triggers a 2FA check.
Setting up an authenticator app
Each user adds an authenticator app from My Profile by scanning a QR code or typing the setup key, then confirming with a code the app generates. HighLevel issues 10 backup codes, each usable once, and they can be regenerated from the same page if lost. Only the person who owns the login can add an app; an admin using the login-as feature cannot do it for them. The app entry is tied to one user and one agency, and the agency's name shows in the authenticator. HighLevel recommends apps over SMS or email codes because they resist phishing and SIM-swap attacks.
Where HighLevel requires a second factor
Beyond the login itself, HighLevel adds verification at a few points attackers target. The check for new SaaS sub-accounts exists because scammers were creating accounts with VoIP numbers and disposable email addresses. A phone number used to verify one sub-account cannot verify another for 7 days, the sub-account admin cannot bypass the check, and agency admins can verify a client manually from the Manage Client page when needed.
- Admin-enforced 2FA: portal administrators may require it for all users
- Phone number changes: the code goes to an already verified email, phone or app, never to the new number
- Mobile app sign-in: users choose email or phone for the one-time code
- New SaaS sub-accounts: agencies can require an SMS code before a client buys phone numbers
- HIPAA add-on: the $297 a month package includes MFA enforcement
Single sign-on for larger teams
Agencies that want staff to log in through their own identity provider can use single sign-on, which HighLevel supports over OpenID Connect only; SAML is on the roadmap but not available. SSO requires the $497 Agency Pro plan and a white-label domain that is already configured, and any agency admin can set it up under Company Settings. Users who sign in through SSO manage their password with that provider. Native HighLevel logins must meet a password policy of at least 8 characters mixing upper and lower case letters, numbers and special characters.
More answers in HighLevel questions. For costs, see GoHighLevel pricing or run the cost calculator.
Sources
- Authenticator app support for two-factor authentication (HighLevel help center)
- HighLevel security and compliance overview
- Mandatory 2FA for phone number updates
- Two-factor authentication for login on the mobile app (changelog)
- 2FA for new SaaS sub-accounts
- Setting up single sign-on (SSO) on HighLevel
- HIPAA compliance with HighLevel