-
Suggestion
-
Resolution: Duplicate
-
None
Problem Definition
At the moment, site-admins of a site are not able to see if the users in their instance have enabled 2FA or not.
For users under our own domain, we can check it through Organization. However, I might have a mix of domain and 3rd party users logging in to my site, and I am not sure if they have deactivated 2FA or not.
Suggested Solution
In the user management, give a label for the users if they have 2FA activated or not.
Why this is important
In order for us to be GDPR compliant, we have to ensure that 2FA is activated for the users.
"since you are able to purchase 2FA as an add-on, the absence of this functionality in our base Atlassian products does not necessarily result in a violation of GDPR" — the problem with this is that I am not able to enforce 2FA for users that are not under my domain.
- is duplicated by
-
ACCESS-102 Enforce security policies for users not on verified domains
- Closed