# How do I enable Associated Accounts with 2FA?

**URL:** https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490
**Category:** Support
**Created:** [September 25, 2019, 3:31pm UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490 "2019-09-25T15:31:11Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![nedbat](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nedbat/32/150103_2.png) [@nedbat](https://meta.discourse.org/u/nedbat)
#### Post date: [September 25, 2019, 3:31pm UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490/1 "2019-09-25T15:31:12Z")

</div>

On my site ([https://discuss.openedx.org](https://discuss.openedx.org)), I don’t see Associated Accounts when I go to edit my profile, like I do when I edit my profile here. But I can’t see anything in settings or plugins that looks like something I have to enable. What am I missing?

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [September 28, 2019, 12:51pm UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490/3 "2019-09-28T12:51:54Z")

</div>

It’s suppressed when 2FA is enabled.

---

<div class="post-metadata">

### Author: ![nedbat](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nedbat/32/150103_2.png) [@nedbat](https://meta.discourse.org/u/nedbat)
#### Post date: [September 28, 2019, 2:18pm UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490/4 "2019-09-28T14:18:30Z")

</div>

Maybe the problem here is I’m misunderstanding what they are for. I wanted a way for people to add their Twitter and GitHub accounts so that other users could see them. For example, to follow people they meet in the forum.

But it’s becoming clearer that the fields I see in my profile here are really only for authentication, and so are not displayed to others. In fact, in the admin panels, they are treated with the same secrecy as email address, with an explicit button to view.

If I want publicly visible Twitter and GitHub handles, do I have to add them as custom user fields myself?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [September 28, 2019, 7:18pm UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490/5 "2019-09-28T19:18:43Z")

</div>

Traditionally that is done in the About Me field as free text, so yes.

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [September 29, 2019, 3:20am UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490/6 "2019-09-29T03:20:06Z")

</div>

You can try [(Retired) Use an ID in a custom user field to link to a user's external profile - #2 by techAPJ](https://meta.discourse.org/t/link-custom-user-field-to-external-website/41218/2) if that is what you need.

---

<div class="post-metadata">

### Author: ![dylanh724](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/dylanh724/32/119642_2.png) [@dylanh724](https://meta.discourse.org/u/dylanh724)
#### Post date: [April 13, 2020, 7:38am UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490/7 "2020-04-13T07:38:09Z")

</div>

Although a necro bump, this is super relevant and at the top of Google right now:

Is there a 2020 solution for this? Currently, [existing forum users that donate via Patreon are locked out from any Discourse rewards](https://meta.discourse.org/t/how-do-existing-discourse-end-users-link-patreon/147766/5). This is a pretty big problem since 2FA is super important and growing in popularity (as it should). We don’t want users to essentially be _punished_ for adding 2FA~

Can’t we just get users to confirm 2fa _before_ connecting any link? It seems outlandish to just remove this feature completely. I have 2FA enabled on Discord, too, for example – should I not be able to connect any account after that?

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [April 13, 2020, 4:02pm UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490/8 "2020-04-13T16:02:42Z")

</div>

The Patreon plugin doesn’t need the social login for it to work. As long as the email match, local logins will work just as fine and the emails will be assigned to their correct groups.

---

<div class="post-metadata">

### Author: ![dylanh724](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/dylanh724/32/119642_2.png) [@dylanh724](https://meta.discourse.org/u/dylanh724)
#### Post date: [April 23, 2020, 6:19am UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490/9 "2020-04-23T06:19:01Z")

</div>

Ohhhh… can we add that to Patreon OP? That’s pretty important. I couldn’t figure out why this guy couldn’t get linked and didn’t know where to turn. This may help others~

However, associated account linking is still pretty nice - some would even say _necessary_. I’m sure not everyone uses the same email for everything (I don’t) for different reasons. Some may also use aliases (eg, `me+someAlias@gmail.com`):

**Can we get associated account linking even when someone 2FA’s up?** Feels like a pretty big downgrade considering how important 2FA is; not the most encouraging to enable it if you lose features.

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [June 3, 2024, 9:27am UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490/10 "2024-06-03T09:27:06Z")

</div>



---

<div class="post-metadata">

### Author: ![roke\_julian\_lockhart](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roke_julian_lockhart/32/540179_2.png) [@roke\_julian\_lockhart](https://meta.discourse.org/u/roke_julian_lockhart)
#### Post date: [April 17, 2026, 1:52pm UTC](https://meta.discourse.org/t/how-do-i-enable-associated-accounts-with-2fa/129490/11 "2026-04-17T13:52:05Z")

</div>

> [@dylanh724](#):
>
> However, associated account linking is still pretty nice - some would even say _necessary_. I’m sure not everyone uses the same email for everything (I don’t) for different reasons. Some may also use aliases (eg, `me+someAlias@gmail.com`):

@dylanh724, that’s my situation. I don’t merely utilise RFC 5233 sub-addresses, but different local parts (albeit, with the same subdomain) per service:

[https://github.com/nextcloud/contacts/issues/3530#issue-1816825315](https://github.com/nextcloud/contacts/issues/3530#issue-1816825315)

Others utilise different local parts and a generic domain that doesn’t relate to them, for which this cannot even theoretically be supported any other way.

Consequently, I want to explain that the undermentioned is nonsensical:

> [@Why is 2FA incompatible with Associated Accounts?](https://meta.discourse.org/t/why-is-2fa-incompatible-with-associated-accounts/355387/3):
>
> > [@Why is 2FA incompatible with Associated Accounts?](https://meta.discourse.org/t/why-is-2fa-incompatible-with-associated-accounts/355387/1):
> >
> > It seems 2FA is mutually exclusive with associated accounts:
> > 
> > > [@Falco](#):
> > >
> > > It’s suppressed when 2FA is enabled.
> > 
> > Why is this?
> 
> […] the reason being is that your associated accounts **can also be compromised** , and AFAIK associated accounts bypass the 2FA restriction on forum accounts. That is why 2FA suppresses associated accounts. Associated accounts can be compromised, especially without 2FA allowing bad-actors to therefore, log into your forum account as well.

I’ve 2FA enabled. Currently, via TOTP, but shall be via CTAP1, when the undermentioned has been resolved:

> **[Allow storing multiple passkeys on one vault item](https://community.bitwarden.com/t/allow-storing-multiple-passkeys-on-one-vault-item/59691?u=rokejulianlockhart)**
>
> Use case: As a user of a website with multiple Top Level Domains (TLD), I want to be able to store multiple passkeys for one Vault Entry. Reason: Passkeys are made so that they are usable only for one relying party ID to avoid phishing attacks...

This is solely for username-plus-password entry. Instead, I’ve also CTAP2 1FA active for the account. It’s also active for all possible OAuth alternatives, thereby rendering the stated rationale for preventing connecting alternative SSO options quite outdated.

It’s also quite confusing for someone who isn’t aware of the restriction:

> **[Shall KDE Bugzilla and/or Discourse ever be connected to Identity or GitLab SSO?](https://discuss.kde.org/t/shall-kde-bugzilla-and-or-discourse-ever-be-connected-to-identity-or-gitlab-sso/46273/2?u=rokejulianlockhart)**
>
> I guess Bugzilla is just too old or otherwise cumbersome to do this. However discuss.kde.org can do this already. The option is called “as a KDE Contributor”.

Consequently, I advise that this not be the default, especially whilst the undermentioned remains:

> [@Passkey option missing on "Enforce second factor on external auth" error screen](https://meta.discourse.org/t/passkey-option-missing-on-enforce-second-factor-on-external-auth-error-screen/397772):
>
> With enforce\_second\_factor\_on\_external\_auth enabled, if a user attempts to log in via social auth they get to this screen: But the option to log in via passkey is missing. It should be added to this screen.

That, plus the general dissuasion toward 2FA, means that it’s a net security negative.
