Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Option to make two factor authentication mandatory #1637

Closed
soullivaneuh opened this issue Mar 16, 2022 · 4 comments
Closed

Option to make two factor authentication mandatory #1637

soullivaneuh opened this issue Mar 16, 2022 · 4 comments
Labels

Comments

@soullivaneuh
Copy link

soullivaneuh commented Mar 16, 2022

Option to make two factor authentication mandatory

Problem

In order to improve our ecosystem security, we need to make two factor authentication (2FA) mandatory.

Solution

A way to set the 2FA as mandatory for any user. Should be configurable at the application level and/or the tenant level.

Alternatives/workarounds

No workaround possible on FusionAuth.

Additional context

Related issues:

Community guidelines

All issues filed in this repository must abide by the FusionAuth community guidelines.

How to vote

Please give us a thumbs up or thumbs down as a reaction to help us prioritize this feature. Feel free to comment if you have a particular need or comment on how this feature should work.

@mooreds
Copy link
Collaborator

mooreds commented Mar 16, 2022

Added some related issues. You may want to review and upvote.

@mooreds mooreds added enhancement New feature or request feature labels Mar 16, 2022
@shortstack
Copy link

would also love to see this. following along.

@robotdan
Copy link
Member

robotdan commented Nov 21, 2022

Planning to deliver via #197.

The current plan is to allow this to be set as required at the tenant, or application level. No current plan to offer more granular configuration to the user level (as an example).

@shortstack or @soullivaneuh do you see a requirement to enforce this down to the user level, and if so, can you describe your use case and how you might want to identify a user that requires MFA during login? Add any comments you have to issue #197 for tracking.

Thanks!

@shortstack
Copy link

@robotdan in our use case, we would only want it at the application level. i don't think we'd need it at the user level, since we want it enforced everywhere. but i could see that being valuable in other scenarios.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants