Business Problem:
Currently, admins can enforce or disable 2FA (two-factor authentication) across the entire organization. However, this setting applies globally—there’s no way to manage 2FA at the user level. In addition, admins are unable to reset 2FA for individual users who lose their authentication keys, leading to situations where users may be permanently locked out without a recovery path.
Desired Outcome:
  • User-level control: Allow admins to disable 2FA for specific users instead of applying changes globally.
  • User recovery support: Provide admins with a secure method to reset or recover 2FA for users who lose access to their authentication keys, ensuring they can regain access without compromising security.