# See who has two-factor or a passkey

BetterShield Ultra’s sign-in report counts two-factor and passkey use by role, lists who a policy is still waiting on, and downloads as a CSV file.

The sign-in report shows how the accounts on this site sign in: who has two-factor on, who holds a passkey, and who a policy is still waiting on. Open **BetterShield › Ultra › Sign-in report**, part of BetterShield Ultra. It reads the site’s own records each time you open it, and changes nothing.

## Who has a second factor

The card opens with one line for the whole site: how many accounts there are, how many have two-factor on, how many hold a passkey, and how many have at least one of the two. Then a row per role:

| Column | What it shows |
|---|---|
| **Role** | Each role on the site, plus **No role** when some accounts have none. |
| **Accounts** | Accounts in that role. |
| **Two-factor** | Of those, accounts with two-factor on. |
| **Passkey** | Accounts holding at least one passkey. |
| **Neither** | Accounts with no second factor of either kind. |
| **Required** | What a policy asks of that role: **two-factor**, **passkey**, both, or nothing. |

An account in two roles is counted in both rows.

**Required** brings every requirement together:

- **Two-factor authentication by role** and **Passkeys by role** on Ultra’s [Sign-in policies](/docs/sign-in-policies/) tab.
- **Require two-factor of a role** and **Sign in with a passkey only** on **Protect › Two-Factor**.
- On multisite, the network’s own requirements on **BetterShield › Network**.

**Download as CSV** saves the role table: for each role, the counts above, the count with either factor, and whether two-factor or a passkey is required. It holds counts only, with no names or email addresses.

## Required, not yet set up

This card lists each account in a required role that does not have what is asked of it yet:

| Column | What it shows |
|---|---|
| **Account** | The display name, with the username after it. |
| **Roles** | The account’s roles. |
| **Missing** | **two-factor**, **passkey**, or both. |

These are the people to follow up with. When nobody is listed, every account a policy applies to has what it asks for, or no policy is set yet.

On a large site, the card checks the first 500 accounts in required roles and says so, for example "Checked the first 500 of 1240 accounts in these roles", so a short list is never read as a complete one.

## Using the report

- **Before you require something.** Tick roles on the Policies tab only once you can see how many people in them are not set up, and how many days they will need.
- **While a grace period runs.** The **Required, not yet set up** list is who still has to act. People are also reminded on their own dashboard.
- **For a client.** The [client report](/docs/client-report/) can carry the same counts by role, under **How accounts sign in**, when **Include how accounts sign in** is on. It never carries the list of who is missing, which stays on this screen.

## Good to know

- On multisite, the report covers the accounts on this site.
- Two-factor here means the authenticator app on the account. A passkey counts in its own column.
- Opening the report needs an account that can manage BetterShield.

## Related

- [Sign-in policies](/docs/sign-in-policies/)
- [Two-factor and passkeys](/docs/two-factor-and-passkeys/)
- [Client report](/docs/client-report/)
- [Multisite networks](/docs/multisite-network/)
