See who has two-factor or a passkey
BetterShield Ultra’s sign-in report counts two-factor and passkey use by role, lists who a policy is still waiting on, and downloads as a CSV file.
The sign-in report shows how the accounts on this site sign in: who has two-factor on, who holds a passkey, and who a policy is still waiting on. Open BetterShield › Ultra › Sign-in report, part of BetterShield Ultra. It reads the site’s own records each time you open it, and changes nothing.
Who has a second factor
The card opens with one line for the whole site: how many accounts there are, how many have two-factor on, how many hold a passkey, and how many have at least one of the two. Then a row per role:
| Column | What it shows |
|---|---|
| Role | Each role on the site, plus No role when some accounts have none. |
| Accounts | Accounts in that role. |
| Two-factor | Of those, accounts with two-factor on. |
| Passkey | Accounts holding at least one passkey. |
| Neither | Accounts with no second factor of either kind. |
| Required | What a policy asks of that role: two-factor, passkey, both, or nothing. |
An account in two roles is counted in both rows.
Required brings every requirement together:
- Two-factor authentication by role and Passkeys by role on Ultra’s Sign-in policies tab.
- Require two-factor of a role and Sign in with a passkey only on Protect › Two-Factor.
- On multisite, the network’s own requirements on BetterShield › Network.
Download as CSV saves the role table: for each role, the counts above, the count with either factor, and whether two-factor or a passkey is required. It holds counts only, with no names or email addresses.
Required, not yet set up
This card lists each account in a required role that does not have what is asked of it yet:
| Column | What it shows |
|---|---|
| Account | The display name, with the username after it. |
| Roles | The account’s roles. |
| Missing | two-factor, passkey, or both. |
These are the people to follow up with. When nobody is listed, every account a policy applies to has what it asks for, or no policy is set yet.
On a large site, the card checks the first 500 accounts in required roles and says so, for example “Checked the first 500 of 1240 accounts in these roles”, so a short list is never read as a complete one.
Using the report
- Before you require something. Tick roles on the Policies tab only once you can see how many people in them are not set up, and how many days they will need.
- While a grace period runs. The Required, not yet set up list is who still has to act. People are also reminded on their own dashboard.
- For a client. The client report can carry the same counts by role, under How accounts sign in, when Include how accounts sign in is on. It never carries the list of who is missing, which stays on this screen.
Good to know
- On multisite, the report covers the accounts on this site.
- Two-factor here means the authenticator app on the account. A passkey counts in its own column.
- Opening the report needs an account that can manage BetterShield.