User not removed from org after turning on 2FA #953

Closed
opened 2026-02-04 23:26:32 +03:00 by OVERLORD · 1 comment
Owner

Originally created by @angelus2014 on GitHub (Feb 25, 2021).

Subject of the issue

After turning on 2FA (2 Step Login) for an organization, users that are not removed from the organization even though the option states:
"Organization members who are not Owners or Administrators and do not have two-step login enabled for their personal account will be removed from the organization and will receive an email notifying them about the change."
Not sure if this is related to issue #981

Your environment

Server version 1.9.0
Web version 2.18.1

  • Install method: Docker
  • Clients used: web ui
  • Reverse proxy and version: none
  • Version of mysql/postgresql: none
  • Other relevant information:

Steps to reproduce

Create an organization without 2FA, add some users and then turn on 2FA.

Expected behaviour

As the app states, the users should be removed from the organization if they haven't turned on 2FA.

Actual behaviour

Nothing happens, users stay in the organization and can login as before. No email is sent.

Relevant logs


Regards,

Angelo Machils

Originally created by @angelus2014 on GitHub (Feb 25, 2021). ### Subject of the issue After turning on 2FA (2 Step Login) for an organization, users that are not removed from the organization even though the option states: "Organization members who are not Owners or Administrators and do not have two-step login enabled for their personal account will be removed from the organization and will receive an email notifying them about the change." Not sure if this is related to issue #981 ### Your environment Server version 1.9.0 Web version 2.18.1 * Install method: Docker * Clients used: web ui * Reverse proxy and version: none * Version of mysql/postgresql: none * Other relevant information: ### Steps to reproduce Create an organization without 2FA, add some users and then turn on 2FA. ### Expected behaviour As the app states, the users should be removed from the organization if they haven't turned on 2FA. ### Actual behaviour Nothing happens, users stay in the organization and can login as before. No email is sent. ### Relevant logs --- Regards, Angelo Machils
OVERLORD added the enhancementduplicate labels 2026-02-04 23:26:32 +03:00
Author
Owner

@BlackDex commented on GitHub (Feb 25, 2021):

We currently do not support 2FA on organizations.
As is mentioned in https://github.com/dani-garcia/bitwarden_rs/wiki.

Marking this as a duplicate of #981

@BlackDex commented on GitHub (Feb 25, 2021): We currently do not support 2FA on organizations. As is mentioned in https://github.com/dani-garcia/bitwarden_rs/wiki. Marking this as a duplicate of #981
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/vaultwarden#953