Uploaded image for project: 'Confluence Cloud'
  1. Confluence Cloud
  2. CONFCLOUD-82713

Ability to prioritize 2FA over email OTP for external users

XMLWordPrintable

    • 2
    • 1
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Summary

      Currently, when the external user security policy requires one-time passcodes (OTP), users are always asked to enter an email OTP even if they already have two-factor authentication (2FA) enabled. Customers request the ability for 2FA-enabled users to authenticate using only 2FA, with email OTP used solely as a fallback for users without 2FA.

      Description

      Atlassian Cloud’s current behavior applies email OTP universally when the external user security policy has OTP enabled. This means external users who have already enabled 2FA are forced to provide both their 2FA app code and an email OTP during login. Customers find this workflow redundant and unnecessarily burdensome, especially since 2FA is already a stronger authentication factor.

      Suggested features

      • Allow admins to configure external user security policy such that:
        • If a user has 2FA enabled, only 2FA is required.
        • If a user does not have 2FA enabled, enforce ID/password + email OTP.
      • Make email OTP act as a true backup method, not an additional mandatory step for 2FA-enabled users.

      Expected outcome

      Admins can enforce stricter security while providing a smoother user experience:

      • External users with 2FA enabled will only need to complete 2FA.
      • External users without 2FA will still be protected through email OTP.
      • This balances security and usability, reduces login friction for 2FA-enabled guests, and supports organizations that want to encourage but not overly complicate MFA adoption.

              Unassigned Unassigned
              9f3b28a42856 Kyungmin Kim
              Votes:
              1 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: