Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Option to disable/enable Code mfa per user #3944

Open
5 tasks done
T-Amin opened this issue Jun 3, 2024 · 0 comments
Open
5 tasks done

Option to disable/enable Code mfa per user #3944

T-Amin opened this issue Jun 3, 2024 · 0 comments
Labels
feat New feature or request.

Comments

@T-Amin
Copy link

T-Amin commented Jun 3, 2024

Preflight checklist

Ory Network Project

No response

Describe your problem

If code MFA is enabled via kratos.yaml, there is currently no way to deactivate this method for specific users.

We intend to use code as a fallback method if a user does not set up any other MFA, such as TOTP or WebAuthn. Once a user sets up another, possibly more secure MFA method, they should be able to deactivate the code method.

Additionally, if code MFA is enabled and required_aal is set to highest_available, users can log in with AAL1 as long as there are no other methods active for AAL2.

Describe your ideal solution

Activate/deactivate code method with settings flow.

Workarounds or alternatives

none

Version

v1.1.0

Additional Context

No response

@T-Amin T-Amin added the feat New feature or request. label Jun 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feat New feature or request.
Projects
None yet
Development

No branches or pull requests

1 participant