Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Possible to remove "I don't have my device" option for Authenticator App TOTP #423

Open
MorhionGendehar opened this issue Jul 27, 2023 · 3 comments

Comments

@MorhionGendehar
Copy link

We are having an issue where users can bypass the TOTP restriction when clicking "I don't have my device" It simply logs them in without MFA. Is there anyway to remove that option?
error

@danmarsden
Copy link
Member

danmarsden commented Jul 28, 2023

You probably have the factors setup incorrectly, can you please add a screenshot that shows how your factors are set up?

@MorhionGendehar
Copy link
Author

image

We want to use the MFA so that only administrators or anyone with 'site administration' has to use the TOTP to access. If I do anything less than this it makes every user authenticate, what did I do wrong?

Thanks for the help!

@danmarsden
Copy link
Member

that does look wrong, unfortunately documentation is still a little weak for this plugin but Moodle HQ's "testing instructions" for pulling this plugin into core has a few scenarios that you might want to try out - take a look at the different testing scenarios on https://tracker.moodle.org/browse/MDL-78509 and you will probably spot something there in the testing scenarios that meets your needs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants