Why 2FA Available and 2FA Enforced Are Not the Same Thing
Security & Compliance

Why 2FA Available and 2FA Enforced Are Not the Same Thing

Plenty of legal software supports two factor authentication, meaning there is a toggle buried in settings that almost nobody turns on. Here is the difference between 2FA as a feature on a sales page and 2FA as something your firm can actually rely on.

Let me be very honest about a pattern we see constantly in legal software, right, a vendor puts "two factor authentication" on their feature list, and technically that is true, there is a toggle somewhere in account settings that a user can turn on if they happen to find it, if they happen to care, and if they happen to get around to it before something forces the issue, and the catch here is that toggle sitting there unused is not actually security, it is the appearance of security, and those are really really different things when it comes to protecting privileged client data.

So let me walk through what "enforced" actually means as opposed to "available," because the gap between those two words is exactly where most firms think they are protected and are not.

0
extra steps to enroll beyond scanning a QR code
10
recovery codes shown once, saved by the user
100%
of logins checked once 2FA is enrolled, no exceptions
3K+
attorneys running their firm on Casely

What "available" usually looks like in practice

Here is the honest pattern, a tool ships 2FA as an opt in setting, it gets mentioned once in an onboarding email nobody reads carefully, and from that point on it is entirely up to each individual user to go find the setting and turn it on, and basically nobody does, not because people do not care about security, but because turning on 2FA has never once in the history of software felt urgent in the moment, there is always something else to do first, and the setting just sits there.

i
The uncomfortable audit question If a managing partner asked right now "which of our attorneys actually have two factor authentication turned on," could the firm answer that in under a minute, with confidence, from inside the software itself? For a lot of firms the honest answer is no, and that gap is the whole problem with "available" security.

What "enforced" actually means in Casely

In Casely, once a user enables 2FA on their account, it is required on every single login from that point forward, there is no way to skip it, no "remember this device forever" loophole that quietly turns enforcement back off, and the setup itself is intentionally simple, scan the QR code with an authenticator app like Google Authenticator, Authy, or 1Password, type the six digit code the app shows you, and you are enrolled.

  1. 01Click Enable 2FA in Settings
  2. 02Scan the QR code with your authenticator app
  3. 03Type the six digit code to confirm the pairing
  4. 04Save the ten recovery codes shown, they are shown once and never again
  5. 05Every login from here on requires the current code

And here is the detail that actually matters for a firm, not just an individual user, right, on the Users page, firm admins can see at a glance who has 2FA enrolled and who does not, it shows up as a clear status next to every name, so instead of security being a hope, it becomes something a managing partner can actually audit in the time it takes to scroll a list.

Feature2FA as an available toggle2FA as Casely enforces it
Who has it turned onWhoever happened to find the settingVisible at a glance on the Users page for every attorney
What happens after enrollingOptional from then on, can be quietly ignoredRequired on every login, no exceptions, no bypass
Recovery if you lose your phoneOften unclear or requires contacting supportTen recovery codes generated at setup, each usable once
Firm wide visibilityNone, it lives in each individual's accountAdmins can see enrollment status for the whole team

Recovery codes exist because phones get lost

Let me be honest about the tradeoff enforced 2FA creates, right, if a code is required on every login, what happens the day someone loses their phone the morning of a hearing, and this is exactly why Casely generates ten recovery codes at the moment you enroll, each one works exactly once, they are shown to you a single time during setup, and the expectation is you save them somewhere safe immediately, a password manager, a printed copy in a locked drawer, and so on, so a lost phone becomes an inconvenience you can solve yourself instead of a locked account and a support ticket during a busy week.

  • Do you know right now how many of your attorneys actually have 2FA turned on
  • Can a user's account be logged into from a new device with just a password, no second factor
  • Would a lost phone lock someone out with no way back in
  • Is enrollment status visible to a firm admin, or only to the individual user
  • Does the login flow ever let someone skip 2FA once it is enabled
  • Are recovery codes generated, shown once, and safely stored somewhere

A stolen password should never be enough on its own

Here is the thing worth sitting with for a second, right, passwords get compromised constantly, not because people are careless, but because passwords get reused across dozens of accounts, because phishing emails have gotten genuinely convincing, and because a single leaked database from some completely unrelated service can hand an attacker a password that happens to match your firm's login too. That is not a hypothetical risk, it is basically the default state of the internet at this point, and it is exactly why relying on a password alone was never actually enough for anything holding privileged information.

The entire value of two factor authentication is that it assumes the password will eventually leak, and builds a second, independent barrier on top of that assumption, so a leaked password becomes an inconvenience for the attacker instead of a way in, and this is precisely why "enforced" has to mean enforced for every login, not just the first one, because an attacker with a stolen password is not going to politely wait for a device the firm considers "trusted," they are going to try logging in from wherever they are, whenever they get the credentials, and the only thing standing between that attempt and actual access is whether the second factor is checked every single time or just some of the time.

Sign out other devices, too Casely also lets any user sign out of every other active session with one click from Settings, for the moment you are not sure if a shared computer or a lost device still has an active login. Pair that with enforced 2FA and a stolen password or an unattended laptop stop being the same thing as a compromised account.

Why this matters more for a law firm than almost anywhere else

At the end of the day, a compromised password is a bad day for most businesses, but for a law firm it is potentially a breach of privileged, confidential client information, the kind of information that if it leaked would not just embarrass the firm, it could genuinely harm a client's case, so the bar for "good enough" security is simply higher here than it is for a typical SaaS product, and treating 2FA as a nice to have toggle instead of a baseline requirement does not match the actual risk a firm is carrying.

The setup itself should not feel like a chore

Let me be honest about one more thing, right, a lot of the resistance to turning on 2FA is not really about the security tradeoff, it is that people expect it to be annoying, a clunky setup flow, an app they have never used before, a code that does not work the first time, and if enrolling feels like a chore, people will keep putting it off no matter how much they intellectually agree it matters.

That is exactly why the enrollment flow in Casely is deliberately just three steps, scan a QR code with whatever authenticator app you already trust, type the six digit code it shows you to confirm the pairing worked, and save your recovery codes, and the whole thing takes under two minutes for someone who has never set up 2FA before, and does that make sense as the actual bar, right, because a security feature that takes two minutes to turn on and is then enforced forever is a completely different proposition than one that requires reading documentation first.

We built it as enforced rather than optional because at the end of the day the whole point of two factor authentication is defeated the moment it becomes something a busy attorney can choose to skip, right, the entire value of the second factor is that it applies every time, without exception, and does that make sense as the actual bar a firm should be holding its software to, not "do you support 2FA" but "can a stolen password alone ever get someone in," and for Casely the answer, once 2FA is enrolled, is simply no.