Require two-factor and passkeys by role
Use BetterShield Ultra’s Policies tab to require two-factor by role at sign-in, remind roles to add a passkey, and stop people removing their own factor.
The Policies tab decides who has to use a second factor, and what counts as one. It is part of BetterShield Ultra, under BetterShield › Ultra › Policies, for accounts that can manage BetterShield. Its three cards save together with Save policies; until you press it, the bar reads Unsaved changes.
Two-factor authentication by role
People in the roles you tick must have two-factor on.
| Option | What it does | Why it matters | Default |
|---|---|---|---|
| Roles | Tick each role that must use two-factor. Every role on the site is listed. | The policy asks nothing of a role that is not ticked. | None ticked |
| Days to set it up | How long each person has, 0 to 90 days. 0 means the very next sign-in. | Switching the policy on shuts nobody out the same day. | 7 |
What the people in those roles see:
- On every dashboard page, a notice says two-factor is required for their role and how many days are left, with a link to set it up: Protect › Two-Factor for people who manage BetterShield, their own profile for everyone else.
- When the days are up, their next sign-in goes from the password to Set up two-factor authentication. They scan the QR code or type the Manual entry key, enter the Code from the app and press Confirm code.
- Keep your backup codes shows ten single-use codes, once. When they confirm they stored them, two-factor is on and the sign-in carries on to the code screen.
Nobody is refused: they are sent to set it up. Sign in as a different account leaves the screen.
- The days count from when the person was first told, or from when their role joined the policy, whichever is later. A role taken off and added back gets the full period again.
- Accounts that never open the dashboard, such as store customers, see no notice. Their first sign-in after the deadline still starts with setup.
- Application passwords keep working. A password sign-in that cannot show a screen, such as over XML-RPC, is refused after the deadline until two-factor is set up.
- Require two-factor of a role on Protect › Two-Factor is a separate requirement with its own clock, and it withholds the dashboard rather than acting at sign-in. When it names roles too, this card says which. See Two-factor and passkeys.
Passkeys by role
People in the roles you tick are asked to hold a passkey. It is a reminder, not a step at sign-in: a notice on every dashboard page links to where they can add one, until they do, and their password signs them in as before. If Sign in with a passkey only on Protect › Two-Factor covers roles, the card names them.
| Option | What it does | Default |
|---|---|---|
| Roles | Tick each role to remind. | None ticked |
| A passkey unlocked with a fingerprint, face or PIN counts as both factors | On: such a passkey signs in without the code. Off: an account with two-factor is always asked for the code, whatever it signed in with. A passkey that only asks for a touch is always asked. | On |
Removing a factor
| Option | What it does | Default |
|---|---|---|
| People in an enforced role cannot turn their own two-factor off or remove their last passkey | Someone in a role ticked above cannot switch off their own two-factor, or delete their only passkey. Someone holding more than one passkey can still remove one. | On |
An administrator can always turn two-factor off for anybody: open the account under Users and press Turn off two-factor for this account. The person then signs in with their password and sets it up again.
Safe mode and recovery
Your recovery link or a printed recovery code starts safe mode. While it lasts, nothing on this tab is enforced, no notice is shown and no countdown starts. See Locked out.
What is recorded
Every save goes into the activity log. A save that asks less of people (a role taken off, more days to set up, a longer trusted-device window, self-removal protection turned off, or a passkey now counting as both factors) is recorded as Two-factor requirement changed and rated high, so it is emailed straight away when instant alerts are on.
With Ask for my password before an action that removes a protection on (Settings › General), saving asks for your password. On multisite, each site sets its own policies.
To see who a policy is still waiting on, open the Sign-in report.