Skip to content

Commit 1c2ccb6

Browse files
vgrljc-clark
andauthored
Require non-2FA first emu admins to enter a recovery code during login [GA] (#53570)
Co-authored-by: jc-clark <jc-clark@github.com>
1 parent 1e90c4a commit 1c2ccb6

File tree

3 files changed

+12
-4
lines changed

3 files changed

+12
-4
lines changed

content/admin/data-residency/getting-started-with-data-residency-for-github-enterprise-cloud.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,12 @@ After we create your enterprise, you will receive an email inviting you to choos
4545
Using an **incognito or private browsing window**:
4646

4747
1. Set the user's password.
48-
1. Save the user's recovery codes.
48+
1. Enable two-factor authentication (2FA), and save the user's recovery codes. See [AUTOTITLE](/authentication/securing-your-account-with-two-factor-authentication-2fa/configuring-two-factor-authentication).
49+
50+
> [!NOTE]
51+
> If 2FA isn't enabled, you will need to enter your enterprise's single sign-on (SSO) recovery code each time you sign in as the setup user. You can download these codes once SSO is enabled.
52+
53+
{% data reusables.enterprise-accounts.emu-recommend-password-manager %}
4954

5055
{% data reusables.enterprise-accounts.emu-password-reset-session %}
5156

content/admin/managing-iam/understanding-iam-for-enterprises/getting-started-with-enterprise-managed-users.md

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -37,12 +37,14 @@ After we create your enterprise, you will receive an email inviting you to choos
3737
Using an **incognito or private browsing window**:
3838

3939
1. Set the user's password.
40-
1. Save the user's recovery codes.
41-
1. Enable two-factor authentication. See [AUTOTITLE](/authentication/securing-your-account-with-two-factor-authentication-2fa/configuring-two-factor-authentication).
40+
1. Enable two-factor authentication (2FA), and save the enterprise recovery codes. See [AUTOTITLE](/admin/managing-iam/managing-recovery-codes-for-your-enterprise/downloading-your-enterprise-accounts-single-sign-on-recovery-codes#downloading-codes-for-an-enterprise-with-enterprise-managed-users).
41+
42+
> [!WARNING]
43+
> All subsequent login attempts for the setup user account will require a successful 2FA challenge response or the use of an enterprise recovery code to complete authentication. To avoid being locked out of your account, save your enterprise recovery codes.
4244
4345
{% data reusables.enterprise-accounts.emu-password-reset-session %}
4446

45-
We strongly recommend **storing the credentials for the setup user** in your company's password management tool. Someone will need to sign in as this user to update authentication settings, migrate to another identity provider or authentication method, or use your enterprise's recovery codes.
47+
{% data reusables.enterprise-accounts.emu-recommend-password-manager %}
4648

4749
## Create a {% data variables.product.pat_generic %}
4850

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
We strongly recommend **storing the credentials for the setup user** in your company's password management tool. Someone will need to sign in as this user to update authentication settings, migrate to another identity provider or authentication method, or use your enterprise's recovery codes.

0 commit comments

Comments
 (0)