<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to re-register 2FA without disabling org-wide forced 2FA in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/unable-to-re-register-2fa-without-disabling-org-wide-forced-2fa/m-p/5404659#M2188</link>
    <description>&lt;P&gt;It seems impossible for Meraki dashboard users to re-register their 2FA authentication token (in the case they're changing their current mobile device) via the Meraki dashboard when the Organization Setting &lt;SPAN&gt;"Force users to set up and use two-factor authentication" is enabled. This seems like a UX gap. Am I missing something?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With "Force users to set up and use two-factor authentication" enabled the user profile only shows an option to "(re)configure offline access on a mobile device":&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bmull_2-1749743536523.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/264318iBD31572C19F4F9D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With "Force users to set up and use two-factor authentication" disabled the user profile shows an option to "Turn off two-factor authentication" and a link to "(re)configure offline access on a mobile device":&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bmull_0-1749743309572.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/264317iBB5554CD85AC628E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When selecting "(re)configure offline access on a mobile device" on a mobile device there is no option to set up 2FA on a new device (this is the same even if the mandatory 2FA org setting is enabled or disabled):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bmull_1-1749743455256.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/264319i9D1E89D8D41ADC11/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The implication here is that organizations that force 2FA for all their users need to temporary disable org-wide mandatory 2FA so that users can turn off two-factor authentication and then re-enroll on their new device. This seems very poorly thought out. There ought to be a 2FA re-enrollment wizard to facilitate this use-case without having to turn off mandatory 2FA for the entire organization by an admin.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jun 2025 15:56:47 GMT</pubDate>
    <dc:creator>bmull</dc:creator>
    <dc:date>2025-06-12T15:56:47Z</dc:date>
    <item>
      <title>Unable to re-register 2FA without disabling org-wide forced 2FA</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/unable-to-re-register-2fa-without-disabling-org-wide-forced-2fa/m-p/5404659#M2188</link>
      <description>&lt;P&gt;It seems impossible for Meraki dashboard users to re-register their 2FA authentication token (in the case they're changing their current mobile device) via the Meraki dashboard when the Organization Setting &lt;SPAN&gt;"Force users to set up and use two-factor authentication" is enabled. This seems like a UX gap. Am I missing something?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With "Force users to set up and use two-factor authentication" enabled the user profile only shows an option to "(re)configure offline access on a mobile device":&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bmull_2-1749743536523.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/264318iBD31572C19F4F9D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With "Force users to set up and use two-factor authentication" disabled the user profile shows an option to "Turn off two-factor authentication" and a link to "(re)configure offline access on a mobile device":&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bmull_0-1749743309572.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/264317iBB5554CD85AC628E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When selecting "(re)configure offline access on a mobile device" on a mobile device there is no option to set up 2FA on a new device (this is the same even if the mandatory 2FA org setting is enabled or disabled):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bmull_1-1749743455256.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/264319i9D1E89D8D41ADC11/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The implication here is that organizations that force 2FA for all their users need to temporary disable org-wide mandatory 2FA so that users can turn off two-factor authentication and then re-enroll on their new device. This seems very poorly thought out. There ought to be a 2FA re-enrollment wizard to facilitate this use-case without having to turn off mandatory 2FA for the entire organization by an admin.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 15:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/unable-to-re-register-2fa-without-disabling-org-wide-forced-2fa/m-p/5404659#M2188</guid>
      <dc:creator>bmull</dc:creator>
      <dc:date>2025-06-12T15:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to re-register 2FA without disabling org-wide forced 2FA</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/unable-to-re-register-2fa-without-disabling-org-wide-forced-2fa/m-p/5404660#M2189</link>
      <description>&lt;P&gt;This is something switching to SAML would resolve.&lt;BR /&gt;&lt;BR /&gt;However I feel your pain as we developed an API solution for managing our admins before SAML was as fully baked as it is now. We have a dummy org that we can add users to w/o 2FA forced that we can put them in and temporarily remove them from something else so that they can make these sorts of changes when necessary.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 16:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/unable-to-re-register-2fa-without-disabling-org-wide-forced-2fa/m-p/5404660#M2189</guid>
      <dc:creator>mloraditch</dc:creator>
      <dc:date>2025-06-12T16:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to re-register 2FA without disabling org-wide forced 2FA</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/unable-to-re-register-2fa-without-disabling-org-wide-forced-2fa/m-p/5404661#M2190</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/128324"&gt;@bmull&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;You are correct, with the current design, &lt;SPAN&gt;"Force users to set up and use two-factor authentication" must be disabled from every organization the account is associated with to complete the process of disabling 2FA for the user—which will then allow the user to turn off 2FA and re-enroll their new device. &lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;P&gt;If you use Duo Mobile, enabling Duo Restore (&lt;A title="https://guide.duo.com/duo-restore#enable-backup-ios" href="https://guide.duo.com/duo-restore#enable-backup-ios" target="_blank" rel="external noopener nofollow noreferrer"&gt;iOS&lt;/A&gt;, &lt;A title="https://guide.duo.com/duo-restore#android" href="https://guide.duo.com/duo-restore#android" target="_blank" rel="external noopener nofollow noreferrer"&gt;Android&lt;/A&gt;) will allow for easier account recovery to the new device.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 12 Jun 2025 19:26:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/unable-to-re-register-2fa-without-disabling-org-wide-forced-2fa/m-p/5404661#M2190</guid>
      <dc:creator>bperezgo</dc:creator>
      <dc:date>2025-06-12T19:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to re-register 2FA without disabling org-wide forced 2FA</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/unable-to-re-register-2fa-without-disabling-org-wide-forced-2fa/m-p/5404662#M2191</link>
      <description>&lt;P&gt;This is 100% a design flaw.  I would call it a bug.&lt;/P&gt;&lt;P&gt;Not a fix; are you aware of email plus codes?  After the username part, you can put a + and another bit of text, and it will still go to your email address.  For example, these will all get delivered to the same place:&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:user+phone1@comapny.com" target="_blank" rel="nofollow noopener noreferrer"&gt;user+phone1@comapny.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:user+phone2@comapny.com" target="_blank" rel="nofollow noopener noreferrer"&gt;user+phone2@comapny.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;My horrible solution, sign up as a second administrator using a plus code email address,&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 03:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/unable-to-re-register-2fa-without-disabling-org-wide-forced-2fa/m-p/5404662#M2191</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2025-06-13T03:13:09Z</dc:date>
    </item>
  </channel>
</rss>

