GitLab Security & compliance

Group does not require two-factor authentication

Part of the GitLab project posture check · fix arrives as a guide

What it is

The group that owns the project does not enforce two-factor authentication for its members.

Why it matters

A single reused password reaches your source, CI variables, and container registry. Group membership is broad by design, so the number of accounts that could be the weak one is large.

How to fix it

Enable the 2FA requirement in the group settings with a grace period, and communicate the deadline — enforcement blocks access for members who have not enrolled.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.