[Defender Pro] Forced 2FA needs to be cleaner

0

We have started implementing Two Factory Authenitcation using Defender Pro on all of our websites. I keep getting calls from people saying they can’t go anywhere other than their profile. This is because they have not enabled 2FA. I think a better way to do this might be to have a big red box at the top of the profile page telling them they need to activate 2FA to continue with a link down to the activating section. Another option would be to allow an admin to set how many times they can login before 2FA activates and have a message in the users dashboard telling them they need to activate the feature. It seems even telling people in advance doesn’t help them. Thanks.

  • Adam
    • Support Gorilla

    Hi jhanten

    I hope you’re well today!

    Currently, if 2FA is “forced” a user that didn’t set it up yet, will indeed be taken to the profile page in back-end. That page should automatically also scroll down to the 2FA setup where there’s a message that by default says:

    “You are required to setup two-factor authentication to use this site”.

    This message text can also be customized in Two-Factor Auth settings in Defender so you could use that to make it more “strict”.

    But I do agree that it might be relatively easy to miss or even deliberately ignore it and/or to get confused as it doesn’t quite “stand out” so I’ve asked our designers to give it another look to see if/how we could improve that in future.

    I’ve also passed over to the developers for further consideration your idea of additional “regular logins allowed” to be set before 2FA “requirement” is fully applied :slight_smile:

    Best regards,
    Adam

  • Jonathon
    • Site Builder, Child of Zeus

    In my experience users are scrolling back up to the top instead of reading where the focus stops. I guess they think they scrolled by accident or something. That is just what I have been hearing. I’m trying to sort out a way to write instructions for this issue on my end, but I feel like as a user experience this is a bit rough. I am super happy that you have the option to force this and I think all of that works great if the person activates it before it is forced.

    Jonathon

  • Adam
    • Support Gorilla

    Hi jhanten

    Just a small update: I already got a confirmation that our designers will be reviewing that to make it more clear in future. I don’t have an ETA on implementation of the changes (neither any details on the changes themselves yet as it’s only been confirmed just a moment ago) but at least I can tell you that yes – it’s going to be improved in future :slight_smile:

    Thanks again for pointing it out!

    Best regards,
    Adam