Try HighLevel

Does GoHighLevel support two-factor authentication?

Compliance. Answered from HighLevel's own documentation.

We earn a commission if you buy HighLevel through our links, at no extra cost to you. How we make money

Our pick for most agencies

HighLevel Unlimited

$297 a month, or $2,970 a year

  • Unlimited client sub-accounts, unlimited users and contacts
  • CRM, funnels, websites, calendars, reviews
  • Texting, calling and email billed by usage
  • Upgrade to Agency Pro for SaaS Mode
Try HighLevel

HighLevel offers a 14 day free trial on every plan. Card required.

The short answer

Yes. HighLevel logins can be protected with a one-time code sent by email or SMS, or with any TOTP authenticator app such as Google Authenticator, Microsoft Authenticator or Authy. Portal administrators can require two-factor authentication for every user, the mobile app supports it, and changing the phone number on a profile always triggers a 2FA check.

Setting up an authenticator app

Each user adds an authenticator app from My Profile by scanning a QR code or typing the setup key, then confirming with a code the app generates. HighLevel issues 10 backup codes, each usable once, and they can be regenerated from the same page if lost. Only the person who owns the login can add an app; an admin using the login-as feature cannot do it for them. The app entry is tied to one user and one agency, and the agency's name shows in the authenticator. HighLevel recommends apps over SMS or email codes because they resist phishing and SIM-swap attacks.

Where HighLevel requires a second factor

Beyond the login itself, HighLevel adds verification at a few points attackers target. The check for new SaaS sub-accounts exists because scammers were creating accounts with VoIP numbers and disposable email addresses. A phone number used to verify one sub-account cannot verify another for 7 days, the sub-account admin cannot bypass the check, and agency admins can verify a client manually from the Manage Client page when needed.

  • Admin-enforced 2FA: portal administrators may require it for all users
  • Phone number changes: the code goes to an already verified email, phone or app, never to the new number
  • Mobile app sign-in: users choose email or phone for the one-time code
  • New SaaS sub-accounts: agencies can require an SMS code before a client buys phone numbers
  • HIPAA add-on: the $297 a month package includes MFA enforcement

Single sign-on for larger teams

Agencies that want staff to log in through their own identity provider can use single sign-on, which HighLevel supports over OpenID Connect only; SAML is on the roadmap but not available. SSO requires the $497 Agency Pro plan and a white-label domain that is already configured, and any agency admin can set it up under Company Settings. Users who sign in through SSO manage their password with that provider. Native HighLevel logins must meet a password policy of at least 8 characters mixing upper and lower case letters, numbers and special characters.

More answers in HighLevel questions. For costs, see GoHighLevel pricing or run the cost calculator.

Try HighLevel

Sources

  1. Authenticator app support for two-factor authentication (HighLevel help center)
  2. HighLevel security and compliance overview
  3. Mandatory 2FA for phone number updates
  4. Two-factor authentication for login on the mobile app (changelog)
  5. 2FA for new SaaS sub-accounts
  6. Setting up single sign-on (SSO) on HighLevel
  7. HIPAA compliance with HighLevel

HighLevel from $97 a month14 day free trial on every plan

Try HighLevel