5 ms·
Hmm. I'm not sure what you mean. Users by default can use the console to update their 2FA credentials. The only time I have to intervene is when they lose their
by realdavidops 6y ago
Hmm. I'm not sure what you mean. Users by default can use the console to update their 2FA credentials. The only time I have to intervene is when they lose their 2FA as it doesn't really do backup codes. We do require 2FA as a part of our login flows so this is something we're using heavily.
- closeparen 6y agoIt may be better for TOTP; I was looking at U2F and WebAuthn.
- tialaramex 6y agoWhat would admin enrollment even look like for WebAuthn? Do I need to FedEx my FIDO security keys to the company IT security department? I can't imagine any scenario in which you have FIDO keys and admin enrollment and security but I'm prepared to be enlightened.
- closeparen 6y agoYou can assign the user a temporary password so that they get prompted to enroll their credential on first login. But: a) Because the password is assigned first, it has higher priority, so subsequent logins will prompt for password first until the admin manually changes the user's credential ordering to put the WebAuthn (passwordless) token higher. The user's credential priority overrides the order of challenges in the login flow. b) There is no option to add or replace one of these credentials, or manage credential ordering yourself, in the end-user webapp that does profile editing / password updates. An admin may be able to reset your account so that you get the first-login experience again and can enroll new credentials.
- tialaramex 6y agoBlergh. I guess maybe this can be both safe and effective while just being really inconvenient, but my instinct is that on the whole it's just going to be inconvenient without being safe or effective. Nobody should have designed something like this, for WebAuthn in particular the standard is explicit about the desire for multiple tokens. Lots of the design is more complicated so as to support that capability.