Role Enforcement for Two Factor

Description

Role Enforcement for Two Factor makes two-factor authentication mandatory for the user roles you choose. It’s an add-on for the Two Factor plugin, which provides the two-factor methods.

When a user in a selected role hasn’t set up any two-factor method:

  • After logging in, they’re sent to their profile instead of the page they asked for.
  • Any other dashboard page sends them back to their profile, where a notice and a dialog explain what to do.
  • Once they set up at least one method, the dashboard works as usual.

Users in other roles aren’t affected, and nothing is enforced until you select at least one role.

Enforcement applies to the dashboard only. It doesn’t restrict the front end of the site.

The plugin makes no external requests and collects no data.

Installation

  1. Install and activate the Two Factor plugin.
  2. Install and activate Role Enforcement for Two Factor.
  3. Go to Settings > Role Enforcement for Two Factor, select the roles that must use two-factor authentication, and save.

FAQ

Which roles are enforced after activation?

None. Nothing changes until you select roles in the settings.

Can I lock myself out?

No. Users in a selected role can always reach their profile to set up two-factor authentication, administrators included.

What happens if the Two Factor plugin isn’t active?

Enforcement is paused, and the settings page shows a warning. WordPress doesn’t let you deactivate Two Factor while this plugin is active, so this only happens if Two Factor is removed another way, for example by deleting its folder.

What happens to the settings when I delete the plugin?

They’re removed from the database.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Role Enforcement for Two Factor” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.0.0

  • First release.