Replies: 4 comments 2 replies
-
|
I would like to clarify that we are using a dedicated service account for LDAP synchronization. For this specific account, we would like to disable MFA, while keeping MFA enabled for all other users |
Beta Was this translation helpful? Give feedback.
-
|
You can bind a policy to the MFA stage to skip it in your authentication flow. I use a policy where if I am on my local network it skips the MFA stage. |
Beta Was this translation helpful? Give feedback.
-
|
I figured out how to edit the stage binding within the flow. it was a little bit differend than described here: Unfortunately, every policy I assign (i tried event policy, client ip (local ip) and user and even negated the policys) won´t work. Authentik just ignores the policy and executes the mfa stage either way. Some ideas? |
Beta Was this translation helpful? Give feedback.
-
|
I tried several different ways to achieve this task : Allowing one specific user to bypass 2FA and only one way worked for me (Authentik V2025.10) : Find the Policy 'user-does-not-have-totp' and edit it You should see its expression is : Swap that out for OR for multiple users and a (possibly) more reliable match using email addresses : |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
what is the most elegant way to de-activate mfa for specific users? Afaik there are two options:
a) authentication-flow without mfa step
b) delete mfa devices on user-level
Are there other ways to implement this? Preferably I would like to pause/disable mfa for a subset of users.
Thanks!
Beta Was this translation helpful? Give feedback.
All reactions