<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Why does using a recovery code to remove one MFA method delete all MFA methods?]]></title><description><![CDATA[<p dir="auto">We've observed that when a user removes an MFA method via the themed <code>AccountTwoFactorDisable.ftl</code> hosted page and supplies a <strong>recovery code</strong> instead of a verification code, FusionAuth removes <strong>all</strong> MFA methods from their account, not just the one they intended to remove.</p>
<p dir="auto">The <a href="https://fusionauth.io/docs/lifecycle/authenticate-users/multi-factor-authentication#disable-mfa" rel="nofollow ugc">documentation</a> mentions this behavior when disabling MFA via the API directly, but it's unclear if this is intentional for the hosted pages as well.</p>
<p dir="auto">This can create an awkward user experience. For example, if a user loses their authenticator app (e.g., after switching phones) and uses a recovery code to remove that old method, they unexpectedly lose all their other MFA methods too.</p>
<p dir="auto">Interestingly, when a user <strong>logs in</strong> using a recovery code instead of a verification code, it does <strong>not</strong> remove their MFA methods — it simply consumes that specific recovery code.</p>
<p dir="auto"><strong>Questions:</strong></p>
<ul>
<li>Is this behavior intentional for the hosted pages?</li>
<li>What is the security rationale for removing all MFA methods when a recovery code is used to disable one method?</li>
<li>Is there a way to configure FusionAuth so that using a recovery code only removes the targeted MFA method?</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/topic/3190/why-does-using-a-recovery-code-to-remove-one-mfa-method-delete-all-mfa-methods</link><generator>RSS for Node</generator><lastBuildDate>Fri, 09 Oct 2026 00:42:30 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3190.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 02 Oct 2026 14:08:36 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Why does using a recovery code to remove one MFA method delete all MFA methods? on Fri, 02 Oct 2026 14:08:47 GMT]]></title><description><![CDATA[<p dir="auto">Yes, this is <strong>intentional behavior</strong> in FusionAuth.</p>
<p dir="auto">When a user provides a recovery code to disable an MFA method — whether through the hosted pages or the API — FusionAuth removes <strong>all MFA methods</strong> from the account. The hosted pages use the same underlying MFA API, so the behavior is consistent across both interfaces.</p>
<h2>Why does this happen?</h2>
<p dir="auto">Recovery codes are designed as a <strong>last-resort mechanism</strong>. The assumption is that if a user must resort to a recovery code to disable MFA, they may have lost access to all their authentication factors. Removing all MFA methods ensures the user can regain access and re-enroll fresh methods.</p>
<p dir="auto">When a recovery code is used for disabling MFA:</p>
<ul>
<li><strong>All MFA methods are removed</strong> from the user's account, regardless of which specific <code>methodId</code> was targeted</li>
<li><strong>All remaining recovery codes are invalidated</strong> at the same time</li>
<li>If the user later adds a new MFA method, a brand new set of recovery codes will be generated</li>
</ul>
<h2>Why is login different?</h2>
<p dir="auto">When a user <strong>logs in</strong> with a recovery code (instead of a verification code), FusionAuth only consumes that specific recovery code without removing MFA methods. This is because login is not an administrative action — the user is simply authenticating, not managing their MFA configuration.</p>
<h2>Current limitations</h2>
<p dir="auto">Unfortunately, there is currently <strong>no way to configure FusionAuth</strong> to remove only the targeted MFA method when a recovery code is used. This is a known design constraint.</p>
<h2>Workaround considerations</h2>
<p dir="auto">If this behavior is problematic for your use case, you could:</p>
<ul>
<li>Provide clear messaging to users before they use a recovery code to disable MFA</li>
<li>Implement a custom flow outside the hosted pages that uses the API with tighter control over which methods are removed</li>
<li>Encourage users to contact support or use an alternative recovery flow that doesn't rely on recovery codes for MFA management</li>
</ul>
<p dir="auto">Feedback on this behavior has been passed along to the FusionAuth Product team for future consideration.</p>
<h2>Related Documentation</h2>
<ul>
<li><a href="https://fusionauth.io/docs/lifecycle/authenticate-users/multi-factor-authentication#build-your-own-interface-1" rel="nofollow ugc">Multi-Factor Authentication (MFA) - Disable MFA Guide</a> - Explains the behavior when using recovery codes vs. verification codes to disable MFA</li>
<li><a href="https://fusionauth.io/docs/apis/two-factor/disable-multi-factor" rel="nofollow ugc">Disable Multi-Factor API</a> - API documentation for disabling MFA methods</li>
<li><a href="https://fusionauth.io/docs/lifecycle/authenticate-users/multi-factor-authentication#recovery-codes" rel="nofollow ugc">Recovery Codes Overview</a> - Information about MFA recovery codes and when they're generated</li>
<li><a href="https://fusionauth.io/docs/lifecycle/manage-users/account-management/" rel="nofollow ugc">Self-Service Account Management</a> - Documentation on the hosted account management pages including MFA management</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/post/8717</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8717</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Fri, 02 Oct 2026 14:08:47 GMT</pubDate></item></channel></rss>