2FA: allow multiple methods per user (App + SMS + Email) with a default method and "Sign in another way"

Current behavior Today each user can be configured with only ONE two-factor authentication method: authenticator app, SMS, or email. If that method is not available at login time, the user cannot sign in and an administrator has to reset or change the 2FA configuration. This happens when the phone is lost, broken, or not at hand, when SMS does not arrive, or when email is not reachable.

Proposal Allow each user to have MORE THAN ONE 2FA method enrolled at the same time, similar to Microsoft 365 / Entra ID ("Sign in another way").

  1. Login (Web Portal)

    • The user's DEFAULT method is shown first, as it is today. For example: "Enter the code from your authenticator app".

    • A new link "Sign in another way" opens the list of the other methods the user has enrolled: • Use a code from my authenticator app • Text a code to +39 ••• ••• ••42 • Email a code to d••••@domain.com

    • Phone numbers and email addresses are partially masked.

    • The SMS or email code is sent only when the user picks that method, not before.

    • Optional: "Remember this device for X days".

  2. Administration (Admin Tool / Advanced Security)

    • Global setting: which methods are allowed (App / SMS / Email), with each one enabled or disabled separately.

    • Per user: view the enrolled methods, set the default method, reset one method without resetting the others.

    • Optional policy: "Require at least 2 methods per user" so every user always has a backup.

    • Optional: allow users to add methods and change their default method themselves after a successful 2FA login.

  3. Logging

    • Record in the logs which method was used for each successful or failed 2FA login.

Benefits

  • Fewer lockouts: if one method fails, the user can sign in with another one.

  • Fewer support calls and fewer admin resets of 2FA.

  • Same user experience as Microsoft 365, which our users already know.

  • Security stays the same, because every method is still a second factor enrolled by the user.

A mock-up of the proposed screens is attached. It is based on the current Web Portal 2FA dialog ("Protect your account with 2-step verification").

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board
Custom icon

Remote Access Feature Request

Date

About 3 hours ago

Author

Daniele Picchi

Subscribe to request

Get notified by email when there are changes.