[GH-ISSUE #143] [Mandatory 2FA] Prevent users from disabling 2FA #43

Closed
opened 2026-02-26 05:32:40 +03:00 by kerem · 2 comments
Owner

Originally created by @kimsyversen on GitHub (Nov 11, 2018).
Original GitHub issue: https://github.com/nextcloud/twofactor_gateway/issues/143

Hi!

I'm currently testing twofactor_gateway and see users have the possibility remove/change 2FA method in their profiles. I'm adding users via a bash script and I want to force users using 2FA via SMS when I add them.

How can the possibility to disable 2FA be removed?

Originally created by @kimsyversen on GitHub (Nov 11, 2018). Original GitHub issue: https://github.com/nextcloud/twofactor_gateway/issues/143 Hi! I'm currently testing twofactor_gateway and see users have the possibility remove/change 2FA method in their profiles. I'm adding users via a bash script and I want to force users using 2FA via SMS when I add them. How can the possibility to disable 2FA be removed?
kerem 2026-02-26 05:32:40 +03:00
Author
Owner

@ChristophWurst commented on GitHub (Nov 12, 2018):

Hi, @kimsyversen!

this is not supported right now, but I can see how it would make sense to have such a check for the very last 2FA provider that gets disabled with mandatory 2FA. There are a bunch of edge cases that makes this tricky to implement, so this needs some discussion beforehand.

@rullzer please transfer this to the https://github.com/nextcloud/server repo

<!-- gh-comment-id:437769893 --> @ChristophWurst commented on GitHub (Nov 12, 2018): Hi, @kimsyversen! this is not supported right now, but I can see how it would make sense to have such a check for the very last 2FA provider that gets disabled with [mandatory 2FA](https://github.com/orgs/nextcloud/projects/17). There are a bunch of edge cases that makes this tricky to implement, so this needs some discussion beforehand. @rullzer please transfer this to the https://github.com/nextcloud/server repo
Author
Owner

@putt1ck commented on GitHub (Aug 28, 2019):

I think mandatory 2FA is now part of NC, but I think it's possible for the user with this app to then not configure any option, which locks them out from next login.

<!-- gh-comment-id:525605301 --> @putt1ck commented on GitHub (Aug 28, 2019): I think mandatory 2FA is now part of NC, but I think it's possible for the user with this app to then not configure any option, which locks them out from next login.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/twofactor_gateway-nextcloud#43
No description provided.