<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/e04d2ce8a5ad4569a7f5c0d9da842c0e&quot; frameborder=&quot;0&quot; width=&quot;1920&quot; height=&quot;1440&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>1440</height><width>1920</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>1440</thumbnail_height><thumbnail_width>1920</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/e04d2ce8a5ad4569a7f5c0d9da842c0e-47eb349a8c3789b8.gif</thumbnail_url><duration>566.399</duration><title>How to Enable MFA in Infigo Storefronts</title><description>This Loom explains how to enable and configure multi-factor authentication (MFA) in all Infigo storefronts. It starts with going to Configuration and Settings, General Settings, then Security settings, ticking MFA enabled, and noting that MFA is off by default for new and existing storefronts. Under require MFA, it recommends enforcing authenticator app and security key while leaving email out unless absolutely required. It also covers role selection for required MFA, optional MFA for registered users, Trusted Devices settings (Trust Device Days defaulting to zero), and email link expiry (15 minutes) with throttle (30 seconds), plus TOTP issuer name and that FIDO2 domain and origin can be left blank to be derived from the storefront URL. Click Save, and required-role users will be prompted at their next login via the selected method.</description></oembed>