Make two-factor authentication (2FA) optional

📘

This information is for an admin editing two-factor authentication settings across an entire account. If you're an individual user looking to manage 2FA for your own account, see Manage 2FA on a user account.

Two-factor authentication (2FA) is optional by default. However, if 2FA is enforced on your account, any users required to log in with 2FA can't optionally turn it off in their profiles.

There are two ways to make 2FA optional:

  • For the entire account at once.
  • For specific users.

For the entire account

To disable enforcement and make 2FA optional for an account:

  1. Log in to Cloud Manager.
  2. In the main menu, select Administration > Identity & Access> Settings > Manage 2FA Enforcement
  3. DeselectEnforce two-factor authentication on this account. The user list disappears.
  4. Select I understand this change will be applied immediately.
  5. Click Save.

Once disabled, 2FA is optional for all users. Anyone who has 2FA turned on in their user profile still logs in with 2FA, while those without it set in their profiles log in with a username and password.

For specific users

To make 2FA optional for a specific user only:

  1. Log in to Cloud Manager.
  2. In the main menu, select Administration > Identity & Access> Settings > Manage 2FA Enforcement
  3. Find the user in the list and deselect them. You can deselect multiple users before you save.
📘

Sort users by selection status Selected firstor Not selected first. The sort order freezes when you open the page or explicitly refresh it. Selecting or deselecting individual rows does not immediately reorder the list. Click Refresh to update the order based on your current selections.

  1. Select I understand this change will be applied immediately.
  2. Click Save.

Only the users you just deselected have 2FA as optional and can manage their 2FA status through their own profiles. Any users remaining with a selected status still have 2FA enforced.


Did this page help you?