Search Results :

×

Drupal Offline 2FA Advanced Settings

The Drupal Offline 2FA module provides advanced settings to customize and control the 2FA authentication experience. Configure options such as Grace Period, Flood Control, Backdoor Login, User Permissions, and Remember Device based on your security requirements.These settings help administrators manage authentication attempts, user access, and trusted devices.

  • Contact the miniOrange team to get the Offline 2FA module package.
  • Extract the downloaded module package and upload the offline_2fa module directory to your Drupal site's directory.
  • Navigate to Extend in your Drupal admin console and search for miniOrange Offline 2FA.
  • Enable the module by checking the checkbox and clicking on the Install button.
  • You can configure the module at:

    {BaseURL}/admin/config/people/miniorange-offline-2fa

  • Ensure that the Offline 2FA module is installed, licensed, and activated, and that at least one Offline 2FA method is configured. You can configure a single method or multiple methods based on your requirements.

The Grace Period for 2FA Setup setting allows users to control how many times users can skip 2FA configuration after logging in before they are required to set up a 2FA method.


  • After configuring one or more Offline 2FA methods, navigate to the Settings tab.
  • Under Grace Period for 2FA Setup, locate the Skip Attempts Before Configuration dropdown.
  • Select the number of login attempts users can skip before they are required to configure 2FA.
  • Click Save Settings to apply the configuration.
Drupal Offline 2FA - Settings - Grace Period for 2FA Setup

Note and Contact Us

Note: This setting applies to users who have not yet configured 2FA. Once 2FA is configured, users cannot skip 2FA authentication.

The Flood Control setting helps protect your Drupal site against brute-force attacks by temporarily blocking users who repeatedly fail 2FA verification.


  • After configuring the required Offline 2FA method(s), navigate to the Settings tab and select Flood Control.
  • Under Maximum Failed Attempts, select the maximum number of failed 2FA validation attempts allowed before the user is temporarily blocked.
  • Under Blocking Duration, select how long the user should remain blocked after exceeding the maximum failed attempts.
  • Click Clear All User Attempt Data to clear the recorded failed 2FA attempt data for all users.
  • Click Save Settings to apply the configuration.
Drupal Offline 2FA - Settings - Flood Control

The Backdoor Login feature provides an emergency access option that allows authorized users to bypass 2FA authentication when required. It generates a unique Backdoor Login URL that can be used to access the Drupal site in emergency situations.


  • After configuring the required Offline 2FA method(s), navigate to the Settings tab and select Backdoor Login.
  • Enable the Enable Backdoor Login toggle.
  • A unique Backdoor Login URL will be generated automatically.
  • Click Copy URL to copy the generated URL and store it securely for emergency use.
  • Click Save Settings to apply the configuration.
Drupal Offline 2FA - Backdoor Login

The User Permissions setting controls whether users can manage and reconfigure their own 2FA settings.


  • After configuring the required Offline 2FA methods, navigate to the Settings tab and select User Permissions.
  • By default, Allow Users to Reconfigure 2FA is enabled, allowing users to change their configured 2FA methods and settings.
  • Disable this option if you do not want users to modify their 2FA configurations.
  • Click Save Settings to apply the configuration.
Drupal Offline 2FA - Settings - User Permissions

The Remember Device feature allows users to mark a device as trusted and skip 2FA authentication for a specified period.


  • After configuring the required Offline 2FA method(s), navigate to the Settings tab and select Remember Device.
  • By default, Enable Remember Device is enabled.
  • Under Remember Duration, select how long a trusted device can be remembered before the user is required to complete 2FA again.
  • Under Maximum Remembered Devices, select the maximum number of devices a user can mark as trusted. Older devices are automatically removed when the limit is exceeded.
  • Click Save Settings to apply the configuration.
Drupal Offline 2FA - Remember Device Configuration

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

We'll Reach Out to You at the Earliest!


ADFS_sso ×
Hello there!

Need Help? We are right here!

support