Hi Chistian,

Op 08-12-2021 om 18:17 schreef Christian Mack (christian.m...@uni-konstanz.de):
How does the user get its TOTP initializon vector then?
She/he can not login without it, but can only scan the QR code while
logged into SOGo ;-)

Well obviously it would mean: After the admin forces it, on the next login, those users would be required to setup and activate MFA.

What for?
Either you want to protect your account with 2FA or not.
You can use long sessions, therefore only login once a day.

You could require MFA from WAN, and not require it from LAN/VPN, for example. That's not unusual.

But I understand from your replies that you don't see it that way ;-)

Thanks!

MJ
--
users@sogo.nu
https://inverse.ca/sogo/lists

Reply via email to