# Require two-factor and passkeys by role

Use BetterShield Ultra’s Policies tab to require two-factor by role at sign-in, remind roles to add a passkey, and stop people removing their own factor.

The **Policies** tab decides who has to use a second factor, and what counts as one. It is part of BetterShield Ultra, under **BetterShield › Ultra › Policies**, for accounts that can manage BetterShield. Its three cards save together with **Save policies**; until you press it, the bar reads **Unsaved changes**.

## Two-factor authentication by role

People in the roles you tick must have two-factor on.

| Option | What it does | Why it matters | Default |
|---|---|---|---|
| Roles | Tick each role that must use two-factor. Every role on the site is listed. | The policy asks nothing of a role that is not ticked. | None ticked |
| **Days to set it up** | How long each person has, 0 to 90 days. **0** means the very next sign-in. | Switching the policy on shuts nobody out the same day. | 7 |

What the people in those roles see:

1. On every dashboard page, a notice says two-factor is required for their role and how many days are left, with a link to set it up: **Protect › Two-Factor** for people who manage BetterShield, their own profile for everyone else.
2. When the days are up, their next sign-in goes from the password to **Set up two-factor authentication**. They scan the QR code or type the **Manual entry key**, enter the **Code from the app** and press **Confirm code**.
3. **Keep your backup codes** shows ten single-use codes, once. When they confirm they stored them, two-factor is on and the sign-in carries on to the code screen.

Nobody is refused: they are sent to set it up. **Sign in as a different account** leaves the screen.

- The days count from when the person was first told, or from when their role joined the policy, whichever is later. A role taken off and added back gets the full period again.
- Accounts that never open the dashboard, such as store customers, see no notice. Their first sign-in after the deadline still starts with setup.
- Application passwords keep working. A password sign-in that cannot show a screen, such as over XML-RPC, is refused after the deadline until two-factor is set up.
- **Require two-factor of a role** on **Protect › Two-Factor** is a separate requirement with its own clock, and it withholds the dashboard rather than acting at sign-in. When it names roles too, this card says which. See [Two-factor and passkeys](/docs/two-factor-and-passkeys/).

## Passkeys by role

People in the roles you tick are asked to hold a passkey. It is a reminder, not a step at sign-in: a notice on every dashboard page links to where they can add one, until they do, and their password signs them in as before. If **Sign in with a passkey only** on **Protect › Two-Factor** covers roles, the card names them.

| Option | What it does | Default |
|---|---|---|
| Roles | Tick each role to remind. | None ticked |
| **A passkey unlocked with a fingerprint, face or PIN counts as both factors** | On: such a passkey signs in without the code. Off: an account with two-factor is always asked for the code, whatever it signed in with. A passkey that only asks for a touch is always asked. | On |

## Removing a factor

| Option | What it does | Default |
|---|---|---|
| **People in an enforced role cannot turn their own two-factor off or remove their last passkey** | Someone in a role ticked above cannot switch off their own two-factor, or delete their only passkey. Someone holding more than one passkey can still remove one. | On |

An administrator can always turn two-factor off for anybody: open the account under **Users** and press **Turn off two-factor for this account**. The person then signs in with their password and sets it up again.

## Safe mode and recovery

Your recovery link or a printed recovery code starts safe mode. While it lasts, nothing on this tab is enforced, no notice is shown and no countdown starts. See [Locked out](/docs/locked-out/).

## What is recorded

Every save goes into the activity log. A save that asks less of people (a role taken off, more days to set up, a longer trusted-device window, self-removal protection turned off, or a passkey now counting as both factors) is recorded as **Two-factor requirement changed** and rated high, so it is emailed straight away when instant alerts are on.

With **Ask for my password before an action that removes a protection** on (**Settings › General**), saving asks for your password. On multisite, each site sets its own policies.

To see who a policy is still waiting on, open the [Sign-in report](/docs/sign-in-report/).

## Related

- [Two-factor and passkeys](/docs/two-factor-and-passkeys/)
- [Trusted devices](/docs/trusted-devices/)
- [Sign-in report](/docs/sign-in-report/)
- [Sign-in screens](/docs/sign-in-screens/)
- [Install Ultra](/docs/install-ultra/)
