Replaces the complete list of users for whom two-factor authentication (2FA) is optional. Users on this list can disable 2FA in their profiles even when the account-level enforcement policy requires it.
This list only takes effect when account-level enforcement is on. Run Update account settings with tfa_enforced: true to enforce 2FA.
Changes apply immediately. Users you remove from the optional list who haven't configured 2FA can't log in until they set it up.
This operation fully replaces the entire data object. Any username you omit reverts to the account-level policy. Pass an empty usernames array to remove all exemptions.
The 200 response returns a count, not the full updated list. To confirm what you saved, run List 2FA optional users.
This operation has a specific rate limit.
Permissions and scopes
To call this operation, you need the following:
-
Identity and access permissions. Your user needs a role with these permissions assigned. Learn more.
- Permissions:
update_tfa_optional_users
- Permissions:
-
OAuth scopes. Your user needs these scopes assigned. Learn more.
- Scopes:
account:read_write
- Scopes:
