8 comments on “How to Share Two-factor Authentication to a Single Account With Multiple Users”

  1. I have had this issue with Zoom. Several of us share the Zoom account for the Church. But the Zoom account is set up with the Church’s email account, which also requires two factor authorization.
    So you go to sign in to the Zoom account. It sends the code to the registered email account. This often requires a call to the secretary to get the code to enter. If she is not in the office you may not be able to get the code.
    So what happens is that you do not sign out of the account-ever. Thereby bypassing the security. Zoom lets you do this, other programs don’t.
    Yes, I have my own Zoom account, but need access to the Church’s in order to set up and send out Zoom invitations for the Church account.

    Reply
  2. I use a variety of TFA managers. Preferably Authy but also the Microsoft & Google Authenticators.
    My MS Authenticator apps are on 2 phones & both receive MS requests to authenticate access to various personal & work accounts.
    I would think it should be possible to use MS Authenticator across phones owned by different team members to provide the TFA.

    A related issue is how one excludes someone who has left the team (or has been booted out).

    Reply
  3. Quote: “You can share a TOTP (Time-Based One-Time Password) setup code with trusted teammates so everyone gets their own copy of the code.” End Quote

    Is this setup code also time sensitive, or can it be saved for emergency recovery, such as if the phone on which the app’s installed is damaged and you must set up the authenticator app on another device?

    Ernie

    Reply
  4. Another way is using a password manager. Bitwarden has a provision for using TOTP codes by copying the secret key code in the same passcard as the username and password. Bitwarden uses an organizational model for password sharing. Members of the organization can have access to the shared passcards. As the administrator, I can group passcards into collections and control who has access to which collection. And add or remove members of the organization as needed.

    Reply

Leave a reply:

Before commenting please:

  • Read the article.
  • Comment on the article.
  • No personal information.
  • No spam.

Comments violating those rules will be removed. Comments that don't add value will be removed, including off-topic or content-free comments, or comments that look even a little bit like spam. All comments containing links and certain keywords will be moderated before publication.

I want comments to be valuable for everyone, including those who come later and take the time to read.