“2FA is Required” Error on Users who have Active 2FAs
-
I have a MultiSite running the latest WordFence (7.10.5) and suddenly today I’ve had 3 users notify me that their previously-working 2FA was suddenly not working. In the Network Admin, I could see these users all had “active” 2FAs (not locked out or in grace period). On their individual settings page, I could see their QR code, recovery codes, but there was no way to for me to deactivate or reset their 2FA from my admin access.
Eventually, I figured out how to whitelist each of their IPs to have them log in without 2FA, then instructed them to reconfigure their 2FA (/wp-admin/network/admin.php?page=WFLS). This is temporarily working.
However, I’m worried that it’s not a permanent fix for those users and ones in the future. One user says when she goes to the link above, it still says she need to configure 2FA even after she reset it. And why does it say on my end that these accounts are “active”? Finally, I now see some users listed as “not allowed” who have been “active” for a long time. I just waiting for them to tell me they can’t log in.
Please let me know of any paths forward to ensure my user have easy access to properly-working 2FA. Thanks for your assistance.
- The topic ‘“2FA is Required” Error on Users who have Active 2FAs’ is closed to new replies.