It seems impossible for Meraki dashboard users to re-register their 2FA authentication token (in the case they're changing their current mobile device) via the Meraki dashboard when the Organization Setting "Force users to set up and use two-factor authentication" is enabled. This seems like a UX gap. Am I missing something? With "Force users to set up and use two-factor authentication" enabled the user profile only shows an option to "(re)configure offline access on a mobile device": With "Force users to set up and use two-factor authentication" disabled the user profile shows an option to "Turn off two-factor authentication" and a link to "(re)configure offline access on a mobile device": When selecting "(re)configure offline access on a mobile device" on a mobile device there is no option to set up 2FA on a new device (this is the same even if the mandatory 2FA org setting is enabled or disabled): The implication here is that organizations that force 2FA for all their users need to temporary disable org-wide mandatory 2FA so that users can turn off two-factor authentication and then re-enroll on their new device. This seems very poorly thought out. There ought to be a 2FA re-enrollment wizard to facilitate this use-case without having to turn off mandatory 2FA for the entire organization by an admin.
... View more