The issue is related to the email template configuration for the mfa_deleter role. The mfa_deleter role has additional requirements beyond just assigning the permission - it needs a properly configured notification system to alert users when their MFA is removed by an administrator.

Key Requirements for the mfa_deleter Role

For the mfa_deleter role to work properly, the target user (the user whose MFA is being removed) must be notifiable through at least one verified primary identity:

Verified email: Requires the "Admin two-factor method removal" email template to be configured in your tenant's email settings Verified phone number: Requires the equivalent message template to be configured in your tenant's phone/messaging settings

The system enforces this as a security measure - when a non-admin user removes someone's MFA method using the mfa_deleter role, the affected user must be notified. If the target user doesn't have a verified email or phone number, OR if the corresponding template isn't configured, the operation will fail.

Resolution Steps Navigate to Tenants → [Your Tenant] → Email tab In the Template settings section, locate the "Admin two-factor method removal" field Assign a valid email template to this setting (you may need to create one first if it doesn't exist) Ensure the target users have verified email addresses Test MFA removal again with a user who has the mfa_deleter permission

Note: You only need to configure the notification method (email or phone) that matches the verified identity your target users have. You don't need both configured if all users have verified emails, for example.

Why Admins Can Remove MFA Without This

Users with the full admin role can remove MFA methods without these template requirements because they have elevated privileges. The mfa_deleter role is specifically designed for support teams and has additional safeguards to prevent abuse, including mandatory user notification.

Related Documentation The mfa_deleter Role - Official documentation on the role and its requirements User Support Guide - Remove MFA Method with mfa_deleter - Step-by-step guide for support teams Disable MFA on a User - General MFA management documentation Admin Two-Factor Authentication Method Removed Email Template - Template variables available for customization Tenant Configuration - Understanding tenant-level template settings