Skip to content

MFA enforcement for Cloud Console#23163

Open
bsanchez-the-roach wants to merge 15 commits intomainfrom
DOC-16025
Open

MFA enforcement for Cloud Console#23163
bsanchez-the-roach wants to merge 15 commits intomainfrom
DOC-16025

Conversation

@bsanchez-the-roach
Copy link
Copy Markdown
Contributor

@netlify
Copy link
Copy Markdown

netlify Bot commented Apr 6, 2026

Deploy Preview for cockroachdb-api-docs canceled.

Name Link
🔨 Latest commit 86b4ee0
🔍 Latest deploy log https://app.netlify.com/projects/cockroachdb-api-docs/deploys/69ea6e55ed023c00087463b2

@netlify
Copy link
Copy Markdown

netlify Bot commented Apr 6, 2026

Deploy Preview for cockroachdb-interactivetutorials-docs canceled.

Name Link
🔨 Latest commit 86b4ee0
🔍 Latest deploy log https://app.netlify.com/projects/cockroachdb-interactivetutorials-docs/deploys/69ea6e55db3f710007a134f8

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 6, 2026

@netlify
Copy link
Copy Markdown

netlify Bot commented Apr 6, 2026

Deploy Preview for cockroachdb-docs failed. Why did it fail? →

Name Link
🔨 Latest commit 86b4ee0
🔍 Latest deploy log https://app.netlify.com/projects/cockroachdb-docs/deploys/69ea6e55f137a7000821166c

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 9, 2026

Diagram Anchor Check: Passed

All sql-grammar.html#anchor references in SQL diagram files resolve correctly against stmt_block.html.

Comment thread src/current/cockroachcloud/cloud-api.md Outdated
Comment thread src/current/cockroachcloud/cloud-api.md Outdated

[Organization Admins]({% link cockroachcloud/authorization.md %}#organization-admin) can reset the MFA of any users who have [set up MFA](#set-up-mfa-for-a-password-based-account) for their password-based access. Resetting the MFA will invalidate the user's existing TOTP binding and recovery codes, and it will force the user to go through the enrollment process upon their next login. To reset a user's MFA:

1. Log in to the [CockroachDB {{ site.data.products.cloud }} Console](https://cockroachlabs.cloud) as a user with the [Organization Admin]({% link cockroachcloud/authorization.md %}#organization-admin) role.
Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This flow was in the Figma demo but not the github one, I want to verify that this is actually in the final feature.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was the feature planned but strangely I don't see the designs neither in figma nor github. Can you please point me to the figma link?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread src/current/cockroachcloud/multi-factor-authentication.md Outdated
Comment thread src/current/cockroachcloud/multi-factor-authentication.md Outdated
Comment thread src/current/cockroachcloud/multi-factor-authentication.md Outdated
Comment thread src/current/cockroachcloud/multi-factor-authentication.md Outdated
Comment thread src/current/cockroachcloud/multi-factor-authentication.md Outdated
Comment thread src/current/cockroachcloud/multi-factor-authentication.md Outdated
Comment thread src/current/cockroachcloud/multi-factor-authentication.md Outdated
Comment thread src/current/cockroachcloud/multi-factor-authentication.md Outdated

[Organization Admins]({% link cockroachcloud/authorization.md %}#organization-admin) can reset the MFA of any users who have [set up MFA](#set-up-mfa-for-a-password-based-account) for their password-based access. Resetting the MFA will invalidate the user's existing TOTP binding and recovery codes, and it will force the user to go through the enrollment process upon their next login. To reset a user's MFA:

1. Log in to the [CockroachDB {{ site.data.products.cloud }} Console](https://cockroachlabs.cloud) as a user with the [Organization Admin]({% link cockroachcloud/authorization.md %}#organization-admin) role.
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was the feature planned but strangely I don't see the designs neither in figma nor github. Can you please point me to the figma link?

Comment thread src/current/cockroachcloud/multi-factor-authentication.md Outdated
1. Click **Set up Multi-Factor Authentication on your account**.
1. Read the information on the **Enable MFA enforcement** modal, then click **Set up MFA**.
1. [Set up MFA for your account](#set-up-mfa-for-a-password-based-account).
1. An Organization Admin will now be able to enable or disable the **Multi-Factor Authentication Enforcement** toggle. It is switched on by default.
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correction: MFA toggle is not switched on by default. There are two scenarios:

  1. Admin uses SSO to login: They can come and manually enable MFA option.
  2. Admin uses password to login: They have to setup their own MFA first, once they do that, MFA will be enabled automatically for their org.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants