Why does using a recovery code to remove one MFA method delete all MFA methods?
-
We've observed that when a user removes an MFA method via the themed
AccountTwoFactorDisable.ftlhosted page and supplies a recovery code instead of a verification code, FusionAuth removes all MFA methods from their account, not just the one they intended to remove.The documentation mentions this behavior when disabling MFA via the API directly, but it's unclear if this is intentional for the hosted pages as well.
This can create an awkward user experience. For example, if a user loses their authenticator app (e.g., after switching phones) and uses a recovery code to remove that old method, they unexpectedly lose all their other MFA methods too.
Interestingly, when a user logs in using a recovery code instead of a verification code, it does not remove their MFA methods — it simply consumes that specific recovery code.
Questions:
- Is this behavior intentional for the hosted pages?
- What is the security rationale for removing all MFA methods when a recovery code is used to disable one method?
- Is there a way to configure FusionAuth so that using a recovery code only removes the targeted MFA method?
-
Yes, this is intentional behavior in FusionAuth.
When a user provides a recovery code to disable an MFA method — whether through the hosted pages or the API — FusionAuth removes all MFA methods from the account. The hosted pages use the same underlying MFA API, so the behavior is consistent across both interfaces.
Why does this happen?
Recovery codes are designed as a last-resort mechanism. The assumption is that if a user must resort to a recovery code to disable MFA, they may have lost access to all their authentication factors. Removing all MFA methods ensures the user can regain access and re-enroll fresh methods.
When a recovery code is used for disabling MFA:
- All MFA methods are removed from the user's account, regardless of which specific
methodIdwas targeted - All remaining recovery codes are invalidated at the same time
- If the user later adds a new MFA method, a brand new set of recovery codes will be generated
Why is login different?
When a user logs in with a recovery code (instead of a verification code), FusionAuth only consumes that specific recovery code without removing MFA methods. This is because login is not an administrative action — the user is simply authenticating, not managing their MFA configuration.
Current limitations
Unfortunately, there is currently no way to configure FusionAuth to remove only the targeted MFA method when a recovery code is used. This is a known design constraint.
Workaround considerations
If this behavior is problematic for your use case, you could:
- Provide clear messaging to users before they use a recovery code to disable MFA
- Implement a custom flow outside the hosted pages that uses the API with tighter control over which methods are removed
- Encourage users to contact support or use an alternative recovery flow that doesn't rely on recovery codes for MFA management
Feedback on this behavior has been passed along to the FusionAuth Product team for future consideration.
Related Documentation
- Multi-Factor Authentication (MFA) - Disable MFA Guide - Explains the behavior when using recovery codes vs. verification codes to disable MFA
- Disable Multi-Factor API - API documentation for disabling MFA methods
- Recovery Codes Overview - Information about MFA recovery codes and when they're generated
- Self-Service Account Management - Documentation on the hosted account management pages including MFA management
- All MFA methods are removed from the user's account, regardless of which specific
-
D dan has marked this topic as solved
-
D dan moved this topic from Staged