Once mandatory MFA has been set, administrators should receive an email alert each time a user logs in without completing MFA

Prior to posting check if a similar request does not already exist.
Try to give a name in the user story format (ref. User story - Wikipedia)
Like: As a role I can action, so that expected benefit

Q1. What is the problem that you are trying to solve?
When MFA has been set to mandatory, a user can choose to continue to log in without setting MFA. There is no limit to the users log in. Administrators need to review user settings to check. Email notification of the event would make the administrators aware.

Q2 - Who is impacted?
N/A

Q3 - Why is it important and/or urgent?
The feature would improve general security

Q4 - What is your proposed solution? (optional)
Use this section to be describe how you would solve this problem if you have a preference or ideas on how to move forward. The more complete the proposal the better, so feel free to add:

  • user stories. Examples: as a logged in user I receive an email notification when a password is changed.
  • test scenario in the “given, when, then” format
  • additional functional / non functional requirements.
  • screenshots/wireframes

Q5. Community support
People can vote for this idea to show traction:

  • :ok_woman: Must have: this is critical for me to have this
  • :raising_hand_woman: Should have: this is important for me to have this
  • :tipping_hand_woman: Could have: this could be nice to have
  • :no_good_woman: Won’t have: we should not schedule this (explain why)
0 voters

In my opinion, filling the administrator’s mailbox with messages from users who do not activate MFA when it is required is not the best approach. This can be a little tricky when you have other maintenance or alert emails in the middle to review and you may delete some of them by accident.

Maybe it’s a better solution, like when setting account recovery as mandatory, that the user is prompted to set up MFA upon login and can’t do anything unless they complete the process

1 Like