Policy on resetting accounts after TFA is enabled.

Created on 4 May 2015, over 10 years ago
Updated 29 August 2025, about 16 hours ago

Once #2239973: Deploy two-factor-authentication on drupal.org is deployed. We will need a policy for removing tfa if a user gets locked out.

For accounts that have certain roles, I feel this should required a trusted user to confirm that the other user is who they say they are. This would be via phone call etc.

This issue is to track the communities ideas around this.

🐛 Bug report
Status

Fixed

Component

User account

Created by

🇺🇸United States mlhess

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024