October 14, 2026 Platform Release Notes

Prev Next

Changing 2FA Settings Now Requires Entering a One-Time Password

Note:

This release will take effect on October 14, 2026.

As part of our regularly scheduled security audit and subsequent hardening, CivicPlus Authentication (CivicPlus Single Sign-On) users are now required to provide a valid 2FA code before they can disable or modify their own 2FA configuration.

This change ensures the user modifying their own 2FA is in possession of a device with access to the 2FA method, email, or application.

No change: A user who has lost their device and cannot access their 2FA recovery codes will still need to contact Customer Support to make a change to their 2FA.

Popup window requesting two-factor authentication code for account reset confirmation.

Why it Matters

  • Prevents a hijacked session from being used to silently remove an account's additional security layer.

  • Ensures users prove control of their configured second factor before changing protection settings.

  • Preserves existing 2FA when setup is cancelled or abandoned before completion. (no change)

What Logged-In Users Can Expect

In Account > Security, users will see a verification prompt when they try to:

Verification Methods

  • Authenticator app: Enter the current code generated by the app.

  • Email 2FA: Request and enter the emailed verification code. A countdown timer appears when another code request is temporarily unavailable to prevent two active codes at the same time.

  • Recovery codes: Recovery codes cannot be used to remove or change 2FA. They remain available for sign-in recovery if the user loses access to their device. Recovery codes should be stored in a secure location outside of devices that may get lost or stolen to avoid this scenario. However, users in this position can contact Customer Support for assistance.

Additional Behavior

  • An invalid (for example, expired) code displays an error and keeps the verification prompt open for another attempt.

  • If the user's organization requires 2FA, the user must configure it again at the next sign-in after removing it.

  • If 2FA setup is cancelled or the user leaves before completion, no changes are saved, and the existing sign-in protection remains active.

  • Users who have lost access to their device cannot remove 2FA without verification. They should contact Support for assistance.

What API Users Can Expect

  • Endpoints that disable or reset a user's own 2FA now require a valid authenticator-app or email 2FA code in the request body.

  • Requests without a code, or requests using a recovery code, are rejected.

  • Support and service-to-service reset flows continue to work without a user-provided code.

  • Canceling setup midway through the process retains the existing 2FA configuration. No change was made here.

Expected Error Responses

Scenario

Response

Meaning

Invalid verification code

400 — two_factor_proof_invalid

“The supplied code could not be verified.”

No verification code provided

400 — two_factor_proof_invalid

“The supplied code could not be verified.”

(A valid 2FA code is now required to modify existing settings, and any attempts to proceed without one will result in a 400.)

The Authentication SDK includes an optional code field in the updated interface. Existing calls remain compatible, but tests that mock the 2FA client interface must be recompiled.


FAQs

What is the new requirement for changing 2FA settings?

Users are now required to provide a valid 2FA code before they can disable or modify their own 2FA configuration.

When will this change take effect?

This change will take effect on October 14, 2026.

What should I do if I lost my device and cannot access my 2FA recovery codes?

You will need to contact Customer Support to make a change to your 2FA.

What verification methods are available for modifying 2FA settings?

Users can use an authenticator app, email 2FA, or recovery codes (though recovery codes cannot be used to change 2FA settings).

What happens if I enter an invalid verification code?

An error will be displayed, and the verification prompt will remain open for another attempt.