BetterShield

See who has two-factor or a passkey

3 min read

BetterShield Ultra’s sign-in report counts two-factor and passkey use by role, lists who a policy is still waiting on, and downloads as a CSV file.

The sign-in report shows how the accounts on this site sign in: who has two-factor on, who holds a passkey, and who a policy is still waiting on. Open BetterShield › Ultra › Sign-in report, part of BetterShield Ultra. It reads the site’s own records each time you open it, and changes nothing.

Who has a second factor

The card opens with one line for the whole site: how many accounts there are, how many have two-factor on, how many hold a passkey, and how many have at least one of the two. Then a row per role:

ColumnWhat it shows
RoleEach role on the site, plus No role when some accounts have none.
AccountsAccounts in that role.
Two-factorOf those, accounts with two-factor on.
PasskeyAccounts holding at least one passkey.
NeitherAccounts with no second factor of either kind.
RequiredWhat a policy asks of that role: two-factor, passkey, both, or nothing.

An account in two roles is counted in both rows.

Required brings every requirement together:

  • Two-factor authentication by role and Passkeys by role on Ultra’s Sign-in policies tab.
  • Require two-factor of a role and Sign in with a passkey only on Protect › Two-Factor.
  • On multisite, the network’s own requirements on BetterShield › Network.

Download as CSV saves the role table: for each role, the counts above, the count with either factor, and whether two-factor or a passkey is required. It holds counts only, with no names or email addresses.

Required, not yet set up

This card lists each account in a required role that does not have what is asked of it yet:

ColumnWhat it shows
AccountThe display name, with the username after it.
RolesThe account’s roles.
Missingtwo-factor, passkey, or both.

These are the people to follow up with. When nobody is listed, every account a policy applies to has what it asks for, or no policy is set yet.

On a large site, the card checks the first 500 accounts in required roles and says so, for example “Checked the first 500 of 1240 accounts in these roles”, so a short list is never read as a complete one.

Using the report

  • Before you require something. Tick roles on the Policies tab only once you can see how many people in them are not set up, and how many days they will need.
  • While a grace period runs. The Required, not yet set up list is who still has to act. People are also reminded on their own dashboard.
  • For a client. The client report can carry the same counts by role, under How accounts sign in, when Include how accounts sign in is on. It never carries the list of who is missing, which stays on this screen.

Good to know

  • On multisite, the report covers the accounts on this site.
  • Two-factor here means the authenticator app on the account. A passkey counts in its own column.
  • Opening the report needs an account that can manage BetterShield.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield