# Two factor authentication?

**URL:** <https://integration.keap.com/t/two-factor-authentication/14341>\
**Category:** Max Classic\
**Created:** [September 13, 2017, 12:41pm UTC](https://integration.keap.com/t/two-factor-authentication/14341 "2017-09-13T12:41:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charles\_Weir](https://sea1.discourse-cdn.com/flex019/user_avatar/integration.keap.com/charles_weir/32/1014_2.png) [@Charles\_Weir](https://integration.keap.com/u/Charles_Weir)\
**Post date:** [September 13, 2017, 12:41pm UTC](https://integration.keap.com/t/two-factor-authentication/14341/1 "2017-09-13T12:41:23Z")

</div>

In [Prevent users seeing credit card numbers? - #2 by James\_Mefford](https://integration.keap.com/t/prevent-users-seeing-credit-card-numbers/11524/2) we identified that we could perhaps satisfy PCI rules by having a separate admin account that alone had access to sensitive credit card data.

Normally I’d expect a sensitive account (and perhaps all our accounts) to have two-factor authentication, which stops all but the most determined and well-funded attackers dead in their tracks.

Will this be supported at some point, and if not, are there any work-arounds?

- Charles

---

<div class="post-metadata">

**Author:** ![bradb](https://sea1.discourse-cdn.com/flex019/user_avatar/integration.keap.com/bradb/32/13_2.png) [@bradb](https://integration.keap.com/u/bradb)\
**Post date:** [September 13, 2017, 9:32pm UTC](https://integration.keap.com/t/two-factor-authentication/14341/2 "2017-09-13T21:32:13Z")

</div>

We are working on this for our PCI compliance as well. It is coming but not sure on the timeline. I read through the referenced thread, and seems strange that they would require you to jump through hoops for our software. We go through a PCI audit every year and I haven’t heard of this happening for one of our customers. I reached out to our main PCI guru to see if she can maybe help out and answer some of these questions on requirements.
