<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with permissions]]></title><description><![CDATA[A list of topics that have been tagged with permissions]]></description><link>https://fusionauth.io/community/forum/tags/permissions</link><generator>RSS for Node</generator><lastBuildDate>Thu, 08 Oct 2026 01:07:52 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/permissions.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[MFA_deleter role fails with error despite configured email template]]></title><description><![CDATA[
<p dir="auto">The issue is related to the email template configuration for the mfa_deleter role. The mfa_deleter role has additional requirements beyond just assigning the permission - it needs a properly configured notification system to alert users when their MFA is removed by an administrator.</p>
Key Requirements for the mfa_deleter Role
<p dir="auto">For the mfa_deleter role to work properly, the <strong>target user</strong> (the user whose MFA is being removed) must be notifiable through at least one verified primary identity:</p>

<strong>Verified email</strong>: Requires the <strong>"Admin two-factor method removal"</strong> email template to be configured in your tenant's email settings
<strong>Verified phone number</strong>: Requires the equivalent message template to be configured in your tenant's phone/messaging settings

<p dir="auto">The system enforces this as a security measure - when a non-admin user removes someone's MFA method using the mfa_deleter role, the affected user must be notified. If the target user doesn't have a verified email or phone number, OR if the corresponding template isn't configured, the operation will fail.</p>
Resolution Steps

<strong>Navigate to Tenants → [Your Tenant] → Email tab</strong>
In the <strong>Template settings</strong> section, locate the <strong>"Admin two-factor method removal"</strong> field
Assign a valid email template to this setting (you may need to create one first if it doesn't exist)
Ensure the target users have verified email addresses
Test MFA removal again with a user who has the mfa_deleter permission

<p dir="auto"><strong>Note:</strong> You only need to configure the notification method (email or phone) that matches the verified identity your target users have. You don't need both configured if all users have verified emails, for example.</p>
Why Admins Can Remove MFA Without This
<p dir="auto">Users with the full admin role can remove MFA methods without these template requirements because they have elevated privileges. The mfa_deleter role is specifically designed for support teams and has additional safeguards to prevent abuse, including mandatory user notification.</p>
Related Documentation

<a href="https://fusionauth.io/docs/get-started/core-concepts/roles#the-mfa_deleter-role" rel="nofollow ugc">The mfa_deleter Role</a> - Official documentation on the role and its requirements
<a href="https://fusionauth.io/docs/operate/deploy/user-support-guide#remove-an-mfa-method-with-the-mfa_deleter-role" rel="nofollow ugc">User Support Guide - Remove MFA Method with mfa_deleter</a> - Step-by-step guide for support teams
<a href="https://fusionauth.io/docs/lifecycle/authenticate-users/multi-factor-authentication#disable-mfa-on-a-user" rel="nofollow ugc">Disable MFA on a User</a> - General MFA management documentation
<a href="https://fusionauth.io/docs/customize/email-and-messages/email-templates-replacement-variables#admin-two-factor-authentication-method-removed" rel="nofollow ugc">Admin Two-Factor Authentication Method Removed Email Template</a> - Template variables available for customization
<a href="https://fusionauth.io/docs/get-started/core-concepts/tenants" rel="nofollow ugc">Tenant Configuration</a> - Understanding tenant-level template settings

]]></description><link>https://fusionauth.io/community/forum/topic/3184/mfa_deleter-role-fails-with-error-despite-configured-email-template</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3184/mfa_deleter-role-fails-with-error-despite-configured-email-template</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>