# Changing 2 factor auth periodicity to keep members involved

**URL:** https://meta.discourse.org/t/changing-2-factor-auth-periodicity-to-keep-members-involved/378481
**Category:** Support
**Tags:** 2fa
**Created:** [August 13, 2025, 8:03pm UTC](https://meta.discourse.org/t/changing-2-factor-auth-periodicity-to-keep-members-involved/378481 "2025-08-13T20:03:55Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![opcourdis](https://avatars.discourse-cdn.com/v4/letter/o/45deac/32.png) [@opcourdis](https://meta.discourse.org/u/opcourdis)
#### Post date: [August 13, 2025, 8:03pm UTC](https://meta.discourse.org/t/changing-2-factor-auth-periodicity-to-keep-members-involved/378481/1 "2025-08-13T20:03:55Z")

</div>

Hi,

Is there a hidden feature to change the 2 factor auth periodicity or have it requested only when a non previously known IP is spotted?

Why? As much as it enhances security, it can be bothersome to have it required on every connection and take some people away from your community.

If you have a good spam prevention enforcement + email verification on sign up, maybe a periodicity of 1x per week would be good enough.

---

<div class="post-metadata">

### Author: ![nat](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nat/32/235063_2.png) [@nat](https://meta.discourse.org/u/nat)
#### Post date: [August 14, 2025, 3:41am UTC](https://meta.discourse.org/t/changing-2-factor-auth-periodicity-to-keep-members-involved/378481/2 "2025-08-14T03:41:07Z")

</div>

Hmm how often are you getting prompted for 2FA?

Just noting that I’ve never been prompted for 2FA on meta as my session is rarely/never expired.

There are some session settings you can set: `/admin/site_settings/category/all_results?filter=session`

- “Persistent sessions” is enabled by default
- “Maximum session age” is 60 days (1440h) by default

You could try to extend the session age, but I feel like a user who hasn’t opened the community in 60 days should _probably_ be prompted to log in again.

Something else you can explore is also SSO, so there isn’t a need for your user to undergo 2FA.

---

<div class="post-metadata">

### Author: ![opcourdis](https://avatars.discourse-cdn.com/v4/letter/o/45deac/32.png) [@opcourdis](https://meta.discourse.org/u/opcourdis)
#### Post date: [August 14, 2025, 8:14am UTC](https://meta.discourse.org/t/changing-2-factor-auth-periodicity-to-keep-members-involved/378481/3 "2025-08-14T08:14:51Z")

</div>

Hi,

> [@nat](#):
>
> Just noting that I’ve never been prompted for 2FA on meta as my session is rarely/never expired.

On meta,2FA is not enforced. But if we take into account sessions duration even if I enforce it via admin/enforce\_second\_factor, a high session duration will prevent it to be asked so it solves the issue.

Thanks for the administration link !

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [September 13, 2025, 8:14am UTC](https://meta.discourse.org/t/changing-2-factor-auth-periodicity-to-keep-members-involved/378481/4 "2025-09-13T08:14:56Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
