<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with factor]]></title><description><![CDATA[A list of topics that have been tagged with factor]]></description><link>https://fusionauth.io/community/forum/tags/factor</link><generator>RSS for Node</generator><lastBuildDate>Fri, 09 Oct 2026 00:41:27 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/factor.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[Why does using a recovery code to remove one MFA method delete all MFA methods?]]></title><description><![CDATA[<p dir="auto">Yes, this is <strong>intentional behavior</strong> in FusionAuth.</p>
<p dir="auto">When a user provides a recovery code to disable an MFA method — whether through the hosted pages or the API — FusionAuth removes <strong>all MFA methods</strong> from the account. The hosted pages use the same underlying MFA API, so the behavior is consistent across both interfaces.</p>
Why does this happen?
<p dir="auto">Recovery codes are designed as a <strong>last-resort mechanism</strong>. The assumption is that if a user must resort to a recovery code to disable MFA, they may have lost access to all their authentication factors. Removing all MFA methods ensures the user can regain access and re-enroll fresh methods.</p>
<p dir="auto">When a recovery code is used for disabling MFA:</p>

<strong>All MFA methods are removed</strong> from the user's account, regardless of which specific methodId was targeted
<strong>All remaining recovery codes are invalidated</strong> at the same time
If the user later adds a new MFA method, a brand new set of recovery codes will be generated

Why is login different?
<p dir="auto">When a user <strong>logs in</strong> with a recovery code (instead of a verification code), FusionAuth only consumes that specific recovery code without removing MFA methods. This is because login is not an administrative action — the user is simply authenticating, not managing their MFA configuration.</p>
Current limitations
<p dir="auto">Unfortunately, there is currently <strong>no way to configure FusionAuth</strong> to remove only the targeted MFA method when a recovery code is used. This is a known design constraint.</p>
Workaround considerations
<p dir="auto">If this behavior is problematic for your use case, you could:</p>

Provide clear messaging to users before they use a recovery code to disable MFA
Implement a custom flow outside the hosted pages that uses the API with tighter control over which methods are removed
Encourage users to contact support or use an alternative recovery flow that doesn't rely on recovery codes for MFA management

<p dir="auto">Feedback on this behavior has been passed along to the FusionAuth Product team for future consideration.</p>
Related Documentation

<a href="https://fusionauth.io/docs/lifecycle/authenticate-users/multi-factor-authentication#build-your-own-interface-1" rel="nofollow ugc">Multi-Factor Authentication (MFA) - Disable MFA Guide</a> - Explains the behavior when using recovery codes vs. verification codes to disable MFA
<a href="https://fusionauth.io/docs/apis/two-factor/disable-multi-factor" rel="nofollow ugc">Disable Multi-Factor API</a> - API documentation for disabling MFA methods
<a href="https://fusionauth.io/docs/lifecycle/authenticate-users/multi-factor-authentication#recovery-codes" rel="nofollow ugc">Recovery Codes Overview</a> - Information about MFA recovery codes and when they're generated
<a href="https://fusionauth.io/docs/lifecycle/manage-users/account-management/" rel="nofollow ugc">Self-Service Account Management</a> - Documentation on the hosted account management pages including MFA management

]]></description><link>https://fusionauth.io/community/forum/topic/3190/why-does-using-a-recovery-code-to-remove-one-mfa-method-delete-all-mfa-methods</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3190/why-does-using-a-recovery-code-to-remove-one-mfa-method-delete-all-mfa-methods</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>