Plan requirement
| Subscription | Any plan |
| Access | Admin |
The way back in when the phone is gone. They have to be generated in advance, because the moment you need them is the moment you cannot sign in.
How they work
- Each person generates their codes when enrolling in two-factor.
- They store them somewhere safe and separate.
- A code is used once to sign in without the authenticator.
- They generate a new set when the codes run low.
Generate them at enrolment
Not later. Somebody who has lost their phone cannot sign in to generate codes, which is exactly the situation the codes exist for.
Make it part of the enrolment instruction rather than a follow-up.
Not on the same device
Codes stored on the phone with the authenticator are useless when the phone is lost. A password manager on another device, or printed and kept securely, both work.
They are as good as the password plus the phone
Anybody holding a code can sign in. They deserve the same care as a password, which means not in a shared document and not in a chat message.
Have an admin route as well
People will lose both. An admin can reset somebody's two-factor enrolment, and that needs a verification step: confirm who is asking, ideally by voice or in person.
A reset granted on the strength of an email is a hole in the control you just spent effort putting in.
Write down the procedure
Who to contact, how they verify you, how long it takes. Three lines, kept where people can reach them without signing in to Zendesk.
Comments
0 comments
Article is closed for comments.