Running a website · Basics · 1:16 min
Users & roles, requiring 2FA
Compose your own role, create an account and require a second factor (app or passkey) per role.
Goal
Everyone gets their own account with exactly the permissions they need – secured with two-factor sign-in.
Prerequisites
- Permission “users and roles” (default: administrators).
Step by step
Transcript: every step matches one subtitle in the video.
- Administration › Benutzer & Rollen (users & roles): everyone gets their own account.
- First a suitable role: “+ Neue Rolle” (new role), enter a name and tick the permissions.
- Whatever is not ticked stays hidden for the role – e.g. no “Veröffentlichen” (publish).
- “Neuen Benutzer anlegen” (new user): name, email, initial password (hand over in person) and role.
- “Anmeldung & Sicherheit” (sign-in & security): allowed methods – authenticator app, passkeys, passwordless sign-in.
- Choose the second factor per role – e.g. Redaktion (editors): “verlangt (App oder Passkey)” (required).
- “Übergangsfrist” (grace period): 0 days = set up at the next sign-in. Then “Speichern” (save).
- Those affected set up an app or passkey at their next sign-in. Network accounts always use 2FA.
Tips & pitfalls
Tip
Permissions for data tables and requests can be restricted per table (“selected tables only”).
Tip
Lost your phone? Sign in with a recovery code, or reset 2FA on the command line (user:2fa-reset).
Watch out
Do not share accounts – the log attributes changes to people.
Watch out
The “Administration” role always has all permissions and cannot be restricted.