Jump to content

Administrator override / cancellation of 2fa


Recommended Posts

From what I've seen, there is no way for an admin to cancel out another admin's 2fa settings? I'm just thinking that there needs to be a way to allow it to be cancelled should you lose your phone with google authenticator on it or some such. 

Within the googles apps, the administrator users can clear the 2fa settings.  I'm just wary of setting this and losing my phone/having my phone (or my staff's phones) stolen and not being able to get back in. 

Is there a process for this?

I realise some might think this is a security risk, but if it was only full admins who have the ability to adjust the 2fa settings it should be ok? you don't normally set all staff as full admin, I'd imagine most only have 1-2 senior full admins as this enables access to system-wide changed (they can turn 2fa on and off anyway) and all other users with lesser access. 

Just a thought. 

Link to comment
Share on other sites

  • WHMCS Support Manager

Hi @loopmail,

You are correct, there is intentionally not a way in the UI to disable two factor authentication for another administrator user.

A Backup Code is provided upon configuration of two factor authentication. If the device is lost/broken, this backup code should be used to login and 2FA can then be disabled.

If the backup code has not been saved, then technical support can assist with disabling 2FA for an account.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated