Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-85546

MFA SMS Factor Triggered on "Log in as" (tool_mfa)

XMLWordPrintable

      When an admin uses the "Log in as" function to impersonate a user, Moodle's Multi-factor Authentication (tool_mfa) plugin treats the session as a real login. It sends an SMS code to the user's mobile device. This creates confusion, concern, and violates user expectations.

      Client Impact:
      A client planning an MFA rollout has flagged this as a critical issue. Their team relies on "Log in as" for daily support and cannot risk unintentionally triggering SMS messages to thousands of users.

      Expected Behavior:
      "Log in as" should not trigger multifactor authentication (MFA) factors, such as SMS. At the very least, this should be configurable.

      Proposed Solution:
      Either (a) exclude impersonation sessions from MFA triggers, or (b) add a setting to control this behavior.

            Unassigned Unassigned
            rebecca.conklin@moodle.com Rebecca Conklin
            Votes:
            13 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.