obiba / agate

OBiBa's user ID provider.
GNU General Public License v3.0
4 stars 7 forks source link

Force 2FA to all users accounts #515

Closed jonathanmassehsj closed 5 months ago

jonathanmassehsj commented 1 year ago

I don't know if this feature exist but I never found the settings to do it. We currently have a policy that we must ensure to have 2FA enabled to all users accounts but I'm not able to find the setting to force 2FA to all users accounts.

Is your feature request related to a problem? Please describe. To have the ability to force 2FA to all users accounts.

Describe the solution you'd like A server to force 2FA to all users accounts.

ymarcon commented 1 year ago

This feature does not exist. Implementing it would affect the login pages (agate, opal, mica) that would redirect to a 2FA registration page. I would estimate 5 days of work. Would you like to fund it?

jonathanmassehsj commented 1 year ago

Thank you @ymarcon , I will check my team about it

thiagomdiniz commented 1 year ago

Looking forward to this feature, as it is a ministerial requirement that imposes in Canada the implementation of the MFA for services exposed on the internet.

ymarcon commented 1 year ago

If it is as important for your institution, by funding the development this feature could be available sooner...

ymarcon commented 5 months ago

Relates to Opal issue obiba/opal#3724

ymarcon commented 5 months ago

admin webapp page login/logout/profile redirects to main pages signin/signout/profile 4725caca6e209535e93954c980be097fb779100d 7e18ecea92f43ff434027c4da8d7163433af68cf

ymarcon commented 5 months ago

feature request extension: option to restrict otp to authenticator app usage (email fallback excluded)