Skip to main content

Working with 2FA, Admin, Full Access, and Highly Privileged Roles

NetSuite 2019.1 and later: Full Access role deprecation & mandatory 2FA, what CloudExtend users need to know

Updated yesterday

Beginning with NetSuite 2019.1, Oracle NetSuite introduced major security changes:

  • Two-Factor Authentication (2FA) is now mandatory for all Highly Privileged Roles, including the Administrator role.

  • The Full Access role is deprecated and cannot be used for most integrations.

  • 2FA cannot be disabled for these roles.

This article explains how these changes impact CloudExtend applications and which authentication options CloudExtend supports.


What Is a “Highly Privileged Role”?

NetSuite defines “highly privileged roles” as roles with deep system access, such as:

  • Administrator

  • Full Access (deprecated)

  • Any custom role with certain powerful permissions

The complete list is documented by NetSuite (link accessible only with login).

These roles are always 2FA-required, and this requirement cannot be removed.


Key Terms

Term

Meaning

TBA

Token-Based Authentication

SSO

Single Sign-On

2FA

Two-Factor Authentication (phone/app verification)


CloudExtend Implications

If you are a CloudExtend customer and logging in via a highly privileged role your options will vary depending on the App you are licensing.

ExtendSync Google Users

Supported

  • Attaching emails

  • Attaching files

  • Autopilot features
    These actions continue working without logging into NetSuite inside the Gmail extension—as long as the user is already logged into NetSuite in a browser session.

Not Supported with 2FA-Required Roles

Users cannot edit NetSuite records inside the Gmail extension using an Admin or other highly privileged role that requires 2FA.

Recommended Approach

Enable a 2FA-compliant integration method:

  • Token-Based Authentication (TBA)

  • Single Sign-On (SSO)


ExtendInsights Excel NetSuite and ExtendSync for Outlook NetSuite Users 

ExtendInsights Excel and ExtendSync Outlook fully support:

  • Token-Based Authentication (TBA)

  • Single Sign-On (SSO)

  • MFA / 2FA

These apps can authenticate using any 2FA-required role as long as the role has the required permissions.

👉 Learn more about the required login permissions here


Need Support?

If you have questions regarding TBA setup, SSO configuration, or role permissions:

💬 Click the chat icon (bottom-right of this page)
or
📧 Email cloudextend-support@celigo.com

We’re here to help ensure your CloudExtend apps remain fully compliant with NetSuite’s latest security policies.

Did this answer your question?