FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    MFA_deleter role fails with error despite configured email template

    Scheduled Pinned Locked Moved Solved
    Frequently Asked Questions (FAQ)
    mfa permissions email-templates tenant configuration
    1
    2
    1
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by

      I'm using FusionAuth 1.69.2 and have granted the mfa_deleter permission to a team role. When users with this permission attempt to disable MFA for other users, the system throws an error.

      What I've verified:

      • Multiple users with the mfa_deleter permission experience this issue
      • The affected users have verified email addresses
      • Email templates are configured under Tenants → Email for "Admin two-factor method removal"
      • The team has these permissions assigned:
        • mfa_deleter
        • user_manager
        • user_support_manager
      • Users with the admin role can successfully delete MFA methods

      Only admin-level users can remove MFA methods, but users with just the mfa_deleter permission cannot. What could be causing this permission issue?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by dan


        The issue is related to the email template configuration for the mfa_deleter role. The mfa_deleter role has additional requirements beyond just assigning the permission - it needs a properly configured notification system to alert users when their MFA is removed by an administrator.

        Key Requirements for the mfa_deleter Role

        For the mfa_deleter role to work properly, the target user (the user whose MFA is being removed) must be notifiable through at least one verified primary identity:

        • Verified email: Requires the "Admin two-factor method removal" email template to be configured in your tenant's email settings
        • Verified phone number: Requires the equivalent message template to be configured in your tenant's phone/messaging settings

        The system enforces this as a security measure - when a non-admin user removes someone's MFA method using the mfa_deleter role, the affected user must be notified. If the target user doesn't have a verified email or phone number, OR if the corresponding template isn't configured, the operation will fail.

        Resolution Steps

        1. Navigate to Tenants → [Your Tenant] → Email tab
        2. In the Template settings section, locate the "Admin two-factor method removal" field
        3. Assign a valid email template to this setting (you may need to create one first if it doesn't exist)
        4. Ensure the target users have verified email addresses
        5. Test MFA removal again with a user who has the mfa_deleter permission

        Note: You only need to configure the notification method (email or phone) that matches the verified identity your target users have. You don't need both configured if all users have verified emails, for example.

        Why Admins Can Remove MFA Without This

        Users with the full admin role can remove MFA methods without these template requirements because they have elevated privileges. The mfa_deleter role is specifically designed for support teams and has additional safeguards to prevent abuse, including mandatory user notification.

        Related Documentation

        • The mfa_deleter Role - Official documentation on the role and its requirements
        • User Support Guide - Remove MFA Method with mfa_deleter - Step-by-step guide for support teams
        • Disable MFA on a User - General MFA management documentation
        • Admin Two-Factor Authentication Method Removed Email Template - Template variables available for customization
        • Tenant Configuration - Understanding tenant-level template settings

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Staged
        • First post
          Last post