Release notes
Team management

Administrators can now require Two-Step Verification (2SV)

A new security capability allows account administrators to require 2SV for users in their organization.
25 November 2025

What is mandatory Two-Step Verification (2SV)?

Mandatory 2SV is a new security functionality that gives Amazon Business administrators the ability to require all member accounts within their organization to enable an extra layer of account protection. With 2SV enabled, users must provide two forms of authentication when signing in:

  1. Something they know: Their Amazon Business password.
  2. Something they have: A second authentication factor such as a mobile phone or authenticator app.

 

This enhanced security measure protects your organization's Amazon Business accounts from unauthorized access, even if passwords or email credentials are compromised. Once enabled, 2SV protects against account takeover attempts through compromised email credentials or password resets. Even if a bad actor gains access to your email and attempts to reset your password, they cannot access your account without the second authentication factor that only you possess.

 

How does it work?

For Administrators:

  • Navigate to your Amazon Business account settings to enable mandatory 2SV at the organization level (administrators can also enable exemptions at the user level).
  • Monitor compliance as members enroll in 2SV.

 

For Users:

  • When your administrator enables mandatory 2SV, you'll be prompted to enroll on your next sign-in.
  • Select your preferred authentication method:
    • SMS: Receive one-time passwords via text message
    • Authenticator App: Generate time-based codes using apps like Google Authenticator or Microsoft Authenticator
  • Complete the enrollment process to continue accessing your Amazon Business account

 

For SSO-Enabled Organizations: If your organization uses Single Sign-On (SSO), we recommend enabling Multi-Factor Authentication (MFA) with your identity provider (such as Okta) rather than Amazon Business 2SV to avoid requiring multiple authentication challenges.

 

Where is it available?

Mandatory 2SV is available to Amazon Business customers in the following regions, providing consistent security standards across your global operations: US, UK, DE, FR, IT, ES, JP, IN, CA, AU, and MX.

 

Learn more about Amazon Business 2SV