MFA_deleter role fails with error despite configured email template
-
I'm using FusionAuth 1.69.2 and have granted the
mfa_deleterpermission to a team role. When users with this permission attempt to disable MFA for other users, the system throws an error.What I've verified:
- Multiple users with the
mfa_deleterpermission experience this issue - The affected users have verified email addresses
- Email templates are configured under Tenants → Email for "Admin two-factor method removal"
- The team has these permissions assigned:
mfa_deleteruser_manageruser_support_manager
- Users with the
adminrole can successfully delete MFA methods
Only admin-level users can remove MFA methods, but users with just the
mfa_deleterpermission cannot. What could be causing this permission issue? - Multiple users with the
-
The issue is related to the email template configuration for the
mfa_deleterrole. Themfa_deleterrole has additional requirements beyond just assigning the permission - it needs a properly configured notification system to alert users when their MFA is removed by an administrator.Key Requirements for the
mfa_deleterRoleFor the
mfa_deleterrole to work properly, the target user (the user whose MFA is being removed) must be notifiable through at least one verified primary identity:- Verified email: Requires the "Admin two-factor method removal" email template to be configured in your tenant's email settings
- Verified phone number: Requires the equivalent message template to be configured in your tenant's phone/messaging settings
The system enforces this as a security measure - when a non-admin user removes someone's MFA method using the
mfa_deleterrole, the affected user must be notified. If the target user doesn't have a verified email or phone number, OR if the corresponding template isn't configured, the operation will fail.Resolution Steps
- Navigate to Tenants → [Your Tenant] → Email tab
- In the Template settings section, locate the "Admin two-factor method removal" field
- Assign a valid email template to this setting (you may need to create one first if it doesn't exist)
- Ensure the target users have verified email addresses
- Test MFA removal again with a user who has the
mfa_deleterpermission
Note: You only need to configure the notification method (email or phone) that matches the verified identity your target users have. You don't need both configured if all users have verified emails, for example.
Why Admins Can Remove MFA Without This
Users with the full
adminrole can remove MFA methods without these template requirements because they have elevated privileges. Themfa_deleterrole is specifically designed for support teams and has additional safeguards to prevent abuse, including mandatory user notification.Related Documentation
- The mfa_deleter Role - Official documentation on the role and its requirements
- User Support Guide - Remove MFA Method with mfa_deleter - Step-by-step guide for support teams
- Disable MFA on a User - General MFA management documentation
- Admin Two-Factor Authentication Method Removed Email Template - Template variables available for customization
- Tenant Configuration - Understanding tenant-level template settings
-
D dan has marked this topic as solved
-
D dan moved this topic from Staged