We are also facing this issue: https://github.com/ory/kratos/issues/3856
If a user has 2FA enabled; they are able to disable it with just email authentication; when they should be required to also verify 2FA before this action
magnificent-oxygen-19823
10/08/2024, 3:05 PM
Is this expected behaviour? This seems okay since the user had to login anyway with 2FA to get into the settings page...