# Strengthening GitLab.com security: Mandatory MFA

GitLab is implementing mandatory multi-factor authentication (MFA) for all GitLab.com users who sign in with username and password. The rollout will be phased over coming months with email and in-product notifications. Users should proactively enable MFA through authenticator apps, WebAuthn devices, passkeys, or email verification.

Those using passwords for API authentication should switch to personal access tokens. SSO-only users are exempt unless they also use password-based login.

## Table of contents

- [Why this is happening](https://api.daily.dev/r/5dCyMZi9j?a=why-this-is-happening "Why this is happening")  
- [Key information to know](https://api.daily.dev/r/5dCyMZi9j?a=key-information-to-know "Key information to know")  
- [FAQ](https://api.daily.dev/r/5dCyMZi9j?a=faq "FAQ")

## Additional Information

Jan 09 • 3m read time • From [about.gitlab.com](https://api.daily.dev/r/5dCyMZi9j "about.gitlab.com")

# Tags

[#security](/content/tags/security "Check all #security posts"/index.html)  
[#devops](/content/tags/devops "Check all #devops posts"/index.html)  
[#authentication](/content/tags/authentication "Check all #authentication posts"/index.html)  
[#gitlab](/content/tags/gitlab "Check all #gitlab posts"/index.html)
