We are also facing this issue: <https://github.com...
# feedback
m
We are also facing this issue: https://github.com/ory/kratos/issues/3856 If a user has 2FA enabled; they are able to disable it with just email authentication; when they should be required to also verify 2FA before this action
Is this expected behaviour? This seems okay since the user had to login anyway with 2FA to get into the settings page...