# Discourse ID and 2FA

**URL:** https://meta.discourse.org/t/discourse-id-and-2fa/400910
**Category:** Support
**Tags:** free-plan
**Created:** [April 17, 2026, 3:47pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910 "2026-04-17T15:47:17Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![roke\_julian\_lockhart](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roke_julian_lockhart/32/540179_2.png) [@roke\_julian\_lockhart](https://meta.discourse.org/u/roke_julian_lockhart)
#### Post date: [April 17, 2026, 3:47pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/1 "2026-04-17T15:47:17Z")

</div>

@JammyDodger, I’ve recently registered an account at for a free instance:

> [@I am unable to register for a free Discourse site](https://meta.discourse.org/t/i-am-unable-to-register-for-a-free-discourse-site/400900/1):
>
> [`id.discourse.com/create-site`](https://id.discourse.com/create-site)

There, I appear to experience what [`t/227972`](https://meta.discourse.org/t/cannot-enable-2fa-after-oauth2-login/227972) describes, too:

| OAuth2 SSO | 2FA |
| --- | --- |
| ![](https://global.discourse-cdn.com/meta/original/4X/4/e/1/4e10191a83ee7b1999f98c872d3f752bdb162f0d.png) | ![](https://global.discourse-cdn.com/meta/original/4X/0/0/6/0064bc08320c59fe11c2590b380114439f87562f.png) |

Most documentation appears to indicate that this should be enabled by default:

> [@2FA - do we have to do anything to enable it?](https://meta.discourse.org/t/2fa-do-we-have-to-do-anything-to-enable-it/94609/2):
>
> 2FA was added back in early March. See [Discourse `2.0.0.beta4` Release Notes](https://meta.discourse.org/t/discourse-2-0-0-beta4-release-notes/82446). You (a Discourse site admin) shouldn’t need to do anything.

However, I’ve no option to even enable it, and it’s not enabled by default:

 ![image](https://global.discourse-cdn.com/meta/original/4X/8/2/9/829531b9edf2c5c27bb94ef19a16076772f52429.jpeg)

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [April 17, 2026, 4:21pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/2 "2026-04-17T16:21:26Z")

</div>

Moved your post here, because this is a different issue than the #Contribute > Bug you posted in originally.

Discourse ID is not using OAuth2. It’s functioning, in effect, as an SSO provider, which is different.

To configure 2FA, you’d need to do so at the SSO provider, ID. Specifically [https://id.discourse.com/my/preferences/security](https://id.discourse.com/my/preferences/security).

---

<div class="post-metadata">

### Author: ![roke\_julian\_lockhart](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roke_julian_lockhart/32/540179_2.png) [@roke\_julian\_lockhart](https://meta.discourse.org/u/roke_julian_lockhart)
#### Post date: [April 17, 2026, 5:20pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/4 "2026-04-17T17:20:21Z")

</div>

@jomaxro, thanks. Perhaps, what confused me was that I attempted to set `enforce_second_factor` to “all”, yet wasn’t able to, because I was informed that “You cannot enforce 2FA if local logins are disabled.” If this isn’t too off-topic, what’s the solution to that?

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [April 17, 2026, 6:22pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/5 "2026-04-17T18:22:17Z")

</div>

> [@roke\_julian\_lockhart](#):
>
> You cannot enforce 2FA if local logins are disabled.” If this isn’t too off-topic, what’s the solution to that?

That’s a good question … and one I don’t have the answer too. I’ve looped in the team to find someone who does!

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [April 17, 2026, 7:04pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/14 "2026-04-17T19:04:25Z")

</div>

So I’ve been corrected by the team. Discourse ID _does_ use OAuth2 under the hood - my apologies. I thought it was using a different protocol.

* * *

To your question, we do not support 2FA with external logins. As the message you saw stated, 2FA cannot be enforced without local logins being enabled. We rely on the external login provider (Discourse ID in this case, but this applies to all external providers) to manage 2FA, including enforcement.

---

<div class="post-metadata">

### Author: ![roke\_julian\_lockhart](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roke_julian_lockhart/32/540179_2.png) [@roke\_julian\_lockhart](https://meta.discourse.org/u/roke_julian_lockhart)
#### Post date: [April 17, 2026, 8:37pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/15 "2026-04-17T20:37:57Z")

</div>

@jomaxro, does that mean that, with the free ~~trial~~ plan, I cannot modify that preference? Alternatively, can I somehow disconnect Discourse ID?

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [April 17, 2026, 8:49pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/16 "2026-04-17T20:49:52Z")

</div>

Want to confirm, are you referring to a free trial, or the free _plan_?

---

<div class="post-metadata">

### Author: ![roke\_julian\_lockhart](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roke_julian_lockhart/32/540179_2.png) [@roke\_julian\_lockhart](https://meta.discourse.org/u/roke_julian_lockhart)
#### Post date: [April 17, 2026, 10:07pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/17 "2026-04-17T22:07:05Z")

</div>

@jomaxro, apologies. Free _plan_, I believe:

 ![](https://global.discourse-cdn.com/meta/original/4X/4/5/8/458c47e36928ab4c73e00f182d7ae5b083283955.png)

---

<div class="post-metadata">

### Author: ![supermathie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/supermathie/32/507518_2.png) [@supermathie](https://meta.discourse.org/u/supermathie)
#### Post date: [April 20, 2026, 1:39am UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/18 "2026-04-20T01:39:58Z")

</div>

> [@jomaxro](#):
>
> We rely on the external login provider (Discourse ID in this case, but this applies to all external providers) to manage 2FA, including enforcement.

Question for us: Does the IdP pass along the information of whether or not the user performed MFA to the SP?

I’m thinking of the analogous mechanism to U2F / FIDO - the program can ask for an attestation from the device as to the level of user interaction expected/required for the credential.

If Discourse ID… or similarly any other IdP (SAML? oAuth2? OIDC?) passes this information along to the SP it would be a piece of information we could potentially use.

If not we’re kind of stuck needing to implement MFA post-federated login to get this guarantee.

---

<div class="post-metadata">

### Author: ![pmusaraj](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pmusaraj/32/119489_2.png) [@pmusaraj](https://meta.discourse.org/u/pmusaraj)
#### Post date: [April 20, 2026, 6:04pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/19 "2026-04-20T18:04:34Z")

</div>

> [@supermathie](#):
>
> If Discourse ID… or similarly any other IdP (SAML? oAuth2? OIDC?) passes this information along to the SP it would be a piece of information we could potentially use.

The standards way to do this is via OIDC. Discourse ID is currently built using OAuth2 only. To support an MFA flag, we’d need to implement OIDC on the provider layer and pass the MFA values back and forth for clients that require it.

There are several complications:

- in Discourse core, we have the option to require 2FA for certain user types only (staff or all), we likely need something similar to be supported via ID
- ID allows logins via Google/Apple/Facebook/Github – but they don’t reliably say if the user did complete 2FA when logging in… we may need to implement 2FA on the ID layer and also likely double-2FA some users, not ideal
- is 2FA on the identity provider layer (that is, not on the local instance) sufficient for all consumers? Generally speaking, I think yes, but we’d need to do a bit more research before committing to it

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [May 20, 2026, 6:05pm UTC](https://meta.discourse.org/t/discourse-id-and-2fa/400910/20 "2026-05-20T18:05:32Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
