How it works in a data room
After entering a password, the user must confirm a second factor: a six-digit code from an authenticator app, a push approval, a hardware security key, or a code sent by text message. The administrator can usually make it mandatory for the whole room or for specific groups, and decide how often the check repeats, for example on every login or once per device per month. App-based codes and hardware keys are stronger than text messages, which can be intercepted through SIM swapping; NIST guidance on authentication treats SMS as a restricted option for that reason.
Why it matters in a deal
Most account takeovers start with a reused or phished password. In a room with dozens of outside users, the chance that one of them has a leaked password is high. Requiring a second factor turns a stolen password into a dead end. It also makes the audit trail more trustworthy, because a logged action is much more likely to belong to the named person. Combine it with session timeouts for users who leave laptops open.
Example
A venture-backed fintech in Austin is raising a Series B and shares its room with fourteen funds. The founder makes app-based codes mandatory for all investor groups but allows text messages for two board members who travel often, then reviews the list after the round closes. Our article on two-factor authentication in data rooms compares the options, and the fundraising guide covers the rest of the setup.