1. Concepts
What two-factor authentication does
Two-factor authentication (2FA) requires a time-based one-time passcode from an authenticator app in addition to a password when signing in. Enabling it for a user makes this second step mandatory at their next sign-in.Who can enable it
2FA is enabled per user from their row in the Users module. It requires the Update permission on the Users module, the same permission needed to edit that user’s profile. By default, only the admin role has it.Enrollment
Once required, the authenticator app setup (QR code or manual entry) happens through Zenskar’s identity provider at the user’s next sign-in.2. How-to guides
Enable 2FA for a user
- Go to Users.
- Open the user’s row kebab menu, and select Enable 2 Factor Authentication.
- Confirm.
Troubleshooting
- The action fails with an error: enabling 2FA requires the Update permission on the Users module. The action itself is always visible; without this permission, it fails on click rather than being hidden or disabled.
- User stuck at setup: enrollment runs on the identity provider’s sign-in flow. Confirm they have a TOTP app installed, and have them retry.
- Need to disable 2FA for a user: contact help@zenskar.com.