Skip to content
Administration and Settings

Turning off a colleague's two step verification

Short answer: go to Settings → Users, find the colleague with the green 2FA badge, and click the button to turn off their two-step verification. You confirm with a six-digit code from your own authenticator app. After that they can sign in with their password alone.

What it's for

A colleague who has lost their device and no longer has their recovery codes can't get back in on their own. This is the only route back in that doesn't go through support.

In the user list, everyone with two-step verification gets a green 2FA badge. The button to turn it off only sits next to those people, because there's nothing to turn off for the rest. That badge is also the answer to who on your team actually secures their account; there's no separate report for it.

You need your own two-step verification

If you don't have two-step verification on yourself, you can't turn a colleague's off. The screen explains that and sends you to your own security page.

That looks strict, and it is, with reason. Without that requirement a stolen admin password would be enough to strip the security off your whole team and then take over every account. Everyone's safety would hang on the admin who takes it least seriously. There's deliberately no fallback to your password either, because your password is exactly what an attacker would already have.

Two things you only notice when you hit them. On this button only a fresh code from your app counts, not a recovery code, while on the sign-in screen a recovery code is fine. So if you're living off your recovery codes, you'll get into Sarrai but you can't help your colleague until you've re-paired your own authenticator. And if your account is locked after five failed attempts, the button refuses before your code is even checked. That's a different message from a wrong code: there's nothing wrong with what you typed, you just have to wait out the lock.

Enter a wrong code five times here and your account locks for fifteen minutes, not your colleague's. That lock applies to your whole account, so you can't stay signed in either. A valid code resets the counter.

What happens to your colleague

  1. Their two-step verification goes off. Signing in asks only for their password from then on.
  2. The shared secret is discarded, so the lost device is permanently useless. Even if it turns up later, the codes on it grant no access.
  3. They're signed out of every session, on every device, and all their remembered devices expire. So warn them if they're in the middle of a conversation.
  4. They get an email saying their two-step verification is off, who did it, and with a link to set it up again.

That email isn't a courtesy but a control. If someone ever misused your admin account to strip colleagues' security, that's the only moment the victim finds out themselves. Which is why you can't turn it off.

If the email fails, the change still goes through and you get no error. That's deliberate too: two-step verification is already off at that point, and half-undoing it would leave your colleague in an unclear state. Do watch out with a departing colleague whose address is no longer in use: the notification then reaches nobody.

What it doesn't do

  • You can't use it on yourself. You turn your own two-step verification off through My profile, the Security block.
  • It only touches your own workspace. Users in another workspace are out of reach.
  • It doesn't give you your colleague's recovery codes. You never see those, they're theirs.
  • It turns nothing on. Your colleague decides whether and when to set two-step verification up again. You can't impose it.
  • Only an admin can do this. An operator or content manager doesn't see the button.

Good to know

Turn your own two-step verification on before you need it, not at the moment someone is locked out. Setting it up takes a couple of minutes, and as long as you put it off you can't help anyone.

There's no overview in the app of who turned off whose two-step verification and when. That sits in the server logs, so retrieving it needs support.

Also searched as

"reset an agent's 2FA", "colleague can't sign in because of authenticator", "undo two-step verification for someone else", "why does Sarrai ask for my own code here", "who on my team has 2FA on"

See also

Was this article helpful?

Your feedback helps us improve this article.