KLXM Studio – Home
Get in touch

Running a website · Basics · 1:16 min

Users & roles, requiring 2FA

Compose your own role, create an account and require a second factor (app or passkey) per role.

No sound, with subtitles German and English subtitles – switch them on and off with “CC” in the player. The video is hosted on this server and only loads when you press play. The steps below are the full text of the video.

Goal

Everyone gets their own account with exactly the permissions they need – secured with two-factor sign-in.

Prerequisites

  • Permission “users and roles” (default: administrators).

Step by step

Transcript: every step matches one subtitle in the video.

  1. Administration › Benutzer & Rollen (users & roles): everyone gets their own account.
  2. First a suitable role: “+ Neue Rolle” (new role), enter a name and tick the permissions.
  3. Whatever is not ticked stays hidden for the role – e.g. no “Veröffentlichen” (publish).
  4. “Neuen Benutzer anlegen” (new user): name, email, initial password (hand over in person) and role.
  5. “Anmeldung & Sicherheit” (sign-in & security): allowed methods – authenticator app, passkeys, passwordless sign-in.
  6. Choose the second factor per role – e.g. Redaktion (editors): “verlangt (App oder Passkey)” (required).
  7. “Übergangsfrist” (grace period): 0 days = set up at the next sign-in. Then “Speichern” (save).
  8. Those affected set up an app or passkey at their next sign-in. Network accounts always use 2FA.

Tips & pitfalls

Tip

Permissions for data tables and requests can be restricted per table (“selected tables only”).

Tip

Lost your phone? Sign in with a recovery code, or reset 2FA on the command line (user:2fa-reset).

Watch out

Do not share accounts – the log attributes changes to people.

Watch out

The “Administration” role always has all permissions and cannot be restricted.