Enable MFA for super admin only
Enable MFA for super admin only
4
votes
-
Panoxol Vasonoxol
commented
Not only MFA but the system needs to validate admin email addresses before they are used as login user IDs by sending an email to the address, getting a code, and entering it back on the site. This is to verify that the user entered the intended email address and not someone else's by mistake which could lead to an account take-over situation.
-
Dennis
commented
Enable MFA for super admin only