FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    Why does using a recovery code to remove one MFA method delete all MFA methods?

    Scheduled Pinned Locked Moved Solved
    Frequently Asked Questions (FAQ)
    mfa multi factor authentication recovery-codes
    1
    2
    17
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by

      We've observed that when a user removes an MFA method via the themed AccountTwoFactorDisable.ftl hosted page and supplies a recovery code instead of a verification code, FusionAuth removes all MFA methods from their account, not just the one they intended to remove.

      The documentation mentions this behavior when disabling MFA via the API directly, but it's unclear if this is intentional for the hosted pages as well.

      This can create an awkward user experience. For example, if a user loses their authenticator app (e.g., after switching phones) and uses a recovery code to remove that old method, they unexpectedly lose all their other MFA methods too.

      Interestingly, when a user logs in using a recovery code instead of a verification code, it does not remove their MFA methods — it simply consumes that specific recovery code.

      Questions:

      • Is this behavior intentional for the hosted pages?
      • What is the security rationale for removing all MFA methods when a recovery code is used to disable one method?
      • Is there a way to configure FusionAuth so that using a recovery code only removes the targeted MFA method?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by

        Yes, this is intentional behavior in FusionAuth.

        When a user provides a recovery code to disable an MFA method — whether through the hosted pages or the API — FusionAuth removes all MFA methods from the account. The hosted pages use the same underlying MFA API, so the behavior is consistent across both interfaces.

        Why does this happen?

        Recovery codes are designed as a last-resort mechanism. The assumption is that if a user must resort to a recovery code to disable MFA, they may have lost access to all their authentication factors. Removing all MFA methods ensures the user can regain access and re-enroll fresh methods.

        When a recovery code is used for disabling MFA:

        • All MFA methods are removed from the user's account, regardless of which specific methodId was targeted
        • All remaining recovery codes are invalidated at the same time
        • If the user later adds a new MFA method, a brand new set of recovery codes will be generated

        Why is login different?

        When a user logs in with a recovery code (instead of a verification code), FusionAuth only consumes that specific recovery code without removing MFA methods. This is because login is not an administrative action — the user is simply authenticating, not managing their MFA configuration.

        Current limitations

        Unfortunately, there is currently no way to configure FusionAuth to remove only the targeted MFA method when a recovery code is used. This is a known design constraint.

        Workaround considerations

        If this behavior is problematic for your use case, you could:

        • Provide clear messaging to users before they use a recovery code to disable MFA
        • Implement a custom flow outside the hosted pages that uses the API with tighter control over which methods are removed
        • Encourage users to contact support or use an alternative recovery flow that doesn't rely on recovery codes for MFA management

        Feedback on this behavior has been passed along to the FusionAuth Product team for future consideration.

        Related Documentation

        • Multi-Factor Authentication (MFA) - Disable MFA Guide - Explains the behavior when using recovery codes vs. verification codes to disable MFA
        • Disable Multi-Factor API - API documentation for disabling MFA methods
        • Recovery Codes Overview - Information about MFA recovery codes and when they're generated
        • Self-Service Account Management - Documentation on the hosted account management pages including MFA management

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Staged
        • First post
          Last post