Hi all.
I find the UI to configure 2FA or passkeys for administrators pretty confusing in total.
I have an admin user configured who got both several WebAuthN instances as a second factor (as well as several passkeys registered for “Login with Fido2”, which doesn’t matter for 2FA).
Still, there is no checkmark in the TFA column in the table where all existing administrators are shown for that respective administrator. Seems like a bug?
Then, I find it strange that I can’t completely remove passwords at all. IMHO it would be the safest to authenticate with passkeys only and not allow passwords. This doesn’t seem to be possible, or am I missing how to do it?
And the most confusing thing is when trying to log in to an administrator account which got WebAuthN as a second factor as well as passkeys registered for “Login with Fido2”. I usually need a couple of tries until I get in.
I use different passkeys: two Yubikeys, Firefox on my M2 Mac (which I usually use in a clamshell setup, so I can’t use the fingerprint reader to prove my presence), and passkeys stored on my Pixel 9 Pro, linked via a QR code.
I realize that this is only a very high-level description of the scenario and user experience, but hopefully people can somehow understand and maybe even confirm this sub-optimal user experience.
I’m using webauthn/passkeys wherever it’s possible (literally on many dozens of sites), and the only site where I constantly have issues logging in is mailcow. :-(
I would be very interested in hearing your experience and your view. Many thanks ahead.