Implement two factor authentication If enabled, require a second factor to acquire a session cookie and reject basic authentication attempts (as second factor cannot be presented). Allow previous and next token for clock skew.