Authentication settings cover two-factor authentication (2FA, also called multi-factor authentication), Login.gov, and Security Assertion Markup Language (SAML) single sign-on with an identity provider (IdP). A user's role determines who can require, reset, and configure these settings. This article lists the authentication permissions for each role and for each action.
Roles referenced on this page: Users with the Admin, Group Admin, Portfolio Manager, Operations, Internal Business User, User, or View Only role.
What can my role do?
Use this section to find everything a specific role can and can't do with authentication settings. For a breakdown by action instead, see By action below.
- Can require users to implement 2FA.
- Can implement 2FA for their own account.
- Can set up Login.gov.
- Can reset 2FA so a user can implement it again.
- Can manage SAML, including disabling SAML and setting up an integration with an identity provider.
- Can implement 2FA for their own account.
- Cannot require users to implement 2FA.
- Cannot set up Login.gov.
- Cannot reset 2FA for other users.
- Cannot manage SAML.
- Can implement 2FA for their own account.
- Cannot require users to implement 2FA.
- Cannot set up Login.gov.
- Cannot reset 2FA for other users.
- Cannot manage SAML.
- Can implement 2FA for their own account.
- Cannot require users to implement 2FA.
- Cannot set up Login.gov.
- Cannot reset 2FA for other users.
- Cannot manage SAML.
- Can implement 2FA for their own account.
- Cannot require users to implement 2FA.
- Cannot set up Login.gov.
- Cannot reset 2FA for other users.
- Cannot manage SAML.
- Can implement 2FA for their own account.
- Cannot require users to implement 2FA.
- Cannot set up Login.gov.
- Cannot reset 2FA for other users.
- Cannot manage SAML.
- Can implement 2FA for their own account.
- Cannot require users to implement 2FA.
- Cannot set up Login.gov.
- Cannot reset 2FA for other users.
- Cannot manage SAML.
By action
Permissions key
✅ = Is permitted.
❌ = Not permitted.
➖ = Not applicable and not permitted.
- Enforce 2FA
-
Require users to implement 2FA.
✅ Only Admins can do this.
❌ No other role can require 2FA.
- Implement 2FA
-
Implement 2FA for your own account.
✅ All roles can do this.
- Login.gov
-
Set up Login.gov.
✅ Only Admins can do this.
❌ No other role can set up Login.gov.
- Reset 2FA
-
Reset 2FA so a user can implement it again.
✅ Only Admins can do this.
❌ No other role can reset 2FA.
- SAML
-
Manage SAML: disable SAML, or set up SAML and integrate with an identity provider.
✅ Only Admins can do this.
❌ No other role can manage SAML.
- December 17, 2024: Disable SAML; Login.gov.
- November 25, 2024: Separated from User Permissions and added VRM/TMH roles.
Comments
Please sign in to leave a comment.