Currently, users with the Administrator role must have two-factor authentication (2FA) configured for security reasons. However, when a user is reassigned from the Administrator role to the Agent role, the previous 2FA required/configuration remains active without the customer having an option to deactivate or reset it from the platform.
To resolve this, the customer must open a ticket with the support team, who in turn must escalate the request to the development team for manual management. While this process is being completed, the user is blocked from being able to access the platform, which directly interrupts the customer's operation.
Impact
  • Loss of productivity: The user cannot work while the request is being managed.
  • Operational overhead: It generates unnecessary urgent tickets for support and takes time away from the development team.
Proposed Solution
  • Allow administrators to deactivate or reset 2FA directly from the platform when changing a user's role.
  • Include explicit confirmation, permission restrictions and logging in security audit logs.
Benefits
  • Zero downtime: The user can continue working immediately after the role change.
  • Autonomy and efficiency: Eliminates dependency on support/development and significantly reduces operational tickets.