<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[MFA_deleter role fails with error despite configured email template]]></title><description><![CDATA[<p dir="auto">I'm using FusionAuth 1.69.2 and have granted the <code>mfa_deleter</code> permission to a team role. When users with this permission attempt to disable MFA for other users, the system throws an error.</p>
<p dir="auto">What I've verified:</p>
<ul>
<li>Multiple users with the <code>mfa_deleter</code> permission experience this issue</li>
<li>The affected users have verified email addresses</li>
<li>Email templates are configured under Tenants → Email for "Admin two-factor method removal"</li>
<li>The team has these permissions assigned:
<ul>
<li><code>mfa_deleter</code></li>
<li><code>user_manager</code></li>
<li><code>user_support_manager</code></li>
</ul>
</li>
<li>Users with the <code>admin</code> role can successfully delete MFA methods</li>
</ul>
<p dir="auto">Only admin-level users can remove MFA methods, but users with just the <code>mfa_deleter</code> permission cannot. What could be causing this permission issue?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3184/mfa_deleter-role-fails-with-error-despite-configured-email-template</link><generator>RSS for Node</generator><lastBuildDate>Thu, 08 Oct 2026 01:02:46 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3184.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 01 Oct 2026 16:43:38 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to MFA_deleter role fails with error despite configured email template on Wed, 07 Oct 2026 22:28:15 GMT]]></title><description><![CDATA[<hr />
<p dir="auto">The issue is related to the email template configuration for the <code>mfa_deleter</code> role. The <code>mfa_deleter</code> role has additional requirements beyond just assigning the permission - it needs a properly configured notification system to alert users when their MFA is removed by an administrator.</p>
<h2>Key Requirements for the <code>mfa_deleter</code> Role</h2>
<p dir="auto">For the <code>mfa_deleter</code> role to work properly, the <strong>target user</strong> (the user whose MFA is being removed) must be notifiable through at least one verified primary identity:</p>
<ul>
<li><strong>Verified email</strong>: Requires the <strong>"Admin two-factor method removal"</strong> email template to be configured in your tenant's email settings</li>
<li><strong>Verified phone number</strong>: Requires the equivalent message template to be configured in your tenant's phone/messaging settings</li>
</ul>
<p dir="auto">The system enforces this as a security measure - when a non-admin user removes someone's MFA method using the <code>mfa_deleter</code> role, the affected user must be notified. If the target user doesn't have a verified email or phone number, OR if the corresponding template isn't configured, the operation will fail.</p>
<h2>Resolution Steps</h2>
<ol>
<li><strong>Navigate to Tenants → [Your Tenant] → Email tab</strong></li>
<li>In the <strong>Template settings</strong> section, locate the <strong>"Admin two-factor method removal"</strong> field</li>
<li>Assign a valid email template to this setting (you may need to create one first if it doesn't exist)</li>
<li>Ensure the target users have verified email addresses</li>
<li>Test MFA removal again with a user who has the <code>mfa_deleter</code> permission</li>
</ol>
<p dir="auto"><strong>Note:</strong> You only need to configure the notification method (email or phone) that matches the verified identity your target users have. You don't need both configured if all users have verified emails, for example.</p>
<h2>Why Admins Can Remove MFA Without This</h2>
<p dir="auto">Users with the full <code>admin</code> role can remove MFA methods without these template requirements because they have elevated privileges. The <code>mfa_deleter</code> role is specifically designed for support teams and has additional safeguards to prevent abuse, including mandatory user notification.</p>
<h2>Related Documentation</h2>
<ul>
<li><a href="https://fusionauth.io/docs/get-started/core-concepts/roles#the-mfa_deleter-role" rel="nofollow ugc">The mfa_deleter Role</a> - Official documentation on the role and its requirements</li>
<li><a href="https://fusionauth.io/docs/operate/deploy/user-support-guide#remove-an-mfa-method-with-the-mfa_deleter-role" rel="nofollow ugc">User Support Guide - Remove MFA Method with mfa_deleter</a> - Step-by-step guide for support teams</li>
<li><a href="https://fusionauth.io/docs/lifecycle/authenticate-users/multi-factor-authentication#disable-mfa-on-a-user" rel="nofollow ugc">Disable MFA on a User</a> - General MFA management documentation</li>
<li><a href="https://fusionauth.io/docs/customize/email-and-messages/email-templates-replacement-variables#admin-two-factor-authentication-method-removed" rel="nofollow ugc">Admin Two-Factor Authentication Method Removed Email Template</a> - Template variables available for customization</li>
<li><a href="https://fusionauth.io/docs/get-started/core-concepts/tenants" rel="nofollow ugc">Tenant Configuration</a> - Understanding tenant-level template settings</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/post/8705</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8705</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Wed, 07 Oct 2026 22:28:15 GMT</pubDate></item></channel></rss>