Cyberattacks are becoming more frequent and more sophisticated. According to IBM’s Cost of a Data Breach report and Verizon’s Data Breach Investigations report, exploitation of software vulnerabilities has tripled since 2024, with zero-day exploits tied to ransomware and extortion campaigns as a chief contributor.
- Exploitation of vulnerabilities tripled (Verizon DBIR)
- Average cost of breach in the US: $10.2M (IBM)
- Weak or stolen passwords account for 80% of hacking-related breaches, and credential phishing has increased by 967% since 2022 (CISA & FIDO Alliance)
With threats on the rise, secure logins are more important than ever. Smartsheet already offers enterprise-grade protections like single sign-on (SSO) and multi-factor authentication (MFA). But many users still rely on just a username and password — one of the weakest login options, and a common target for phishing and credential theft. To avoid putting company data at risk, IT teams must enforce modern security standards.
The solution: authenticator-app MFA for all plans
We’re raising the security baseline for everyone. Starting October 30th, Smartsheet will offer authenticator-app MFA, free for all plan types. With this update, every customer — from small teams to global enterprises — can enforce modern, phishing-resistant login security.
Cheat sheet: Understanding login security:
- Username + Password → ❌ Vulnerable
- Password + email code → ⚠️ Still Risky
- Password + Authenticator App → ✅ Strong
- SSO via your organization’s Identity Provider (e.g., Microsoft Entra ID, Okta, Google Workspace) with MFA → 🛡️ Most Secure
- External Collaborator MFA (via Authenticator App) → 🔒 Extends protection beyond employees for Enterprise plans
What’s coming soon:
- Free authenticator-app-based MFA for all plans
- Simple user login with Microsoft/Google Authenticator
- Enterprise-ready governance controls, accessible to all plan types
What it means for you
Admins gain control: Any Smartsheet admin can now enable authenticator-app MFA for their users and collaborators
Users stay secure: Logging in with an authenticator app is quick, familiar, and already part of how most employees access other enterprise tools.
The organization collaborates without compromise: Enterprise plans can implement external MFA, requiring contractors, vendors, and partners to meet the same secure login standards as your employees.
“Adoption lags despite MFA being widely recognized as one of the most effective defenses against cyber attacks...cost is the primary barrier to adoption.” - Cyber readiness institute
We believe every Smartsheet customer deserves access to enterprise-grade authentication – which is why we’re providing this core login security enhancement free for all clients. This reinforces our vision of secure-by-default collaboration, giving every user and organization the confidence that their information is protected at any scale.
Why it matters
For sysadmins and IT/Security leaders, authenticator-app MFA reduces login risk and ensures that every user and collaborator benefits from enterprise-grade protection. By moving beyond weaker methods like email-based passcodes, Smartsheet helps customers defend against phishing, credential theft, and account takeover.
External collaborators held to Internal standards.
Enterprise plans can enable external MFA to require that partners, contractors, and vendors log in with MFA — ensuring everyone who touches your data is protected.
Smartsheet Authenticator-App MFA for login
- Free, simple, and secure
- Enterprise-grade protection
- No extra cost, no barriers
Bottom line:
Smartsheet authenticator-app MFA makes it easy for every organization to safeguard access, protect data, and collaborate without compromise — all at no additional cost.
Get ready for enhanced security! Authenticator-app MFA for login and external collaborators is set to launch late October, so you can plan to enable it in your Smartsheet admin center from November 1!
Curious to dive into the other security and governance controls Smartsheet offers in the meantime? Check out our comprehensive security white paper!