9

I use scopes:

but result data of:

not contains info about exist two-factor auth on google account. Can I get boolean or another value about it?

1 Answer 1

11

Sorry we don't expose If a user has 2 factor auth or not) through API. We have been thinking about this for a while.

We have been doing a lot of things to improve the security for all users (including the ones who have not enabled 2nd factor). This is based on the risk signals and we ask for second factor if the user has a phone # on their account even without a user enabling "strict" 2nd factor. This allows us to protect all users. The difference being in one case 2nd factor is required in all sign-in vs required when we think there is risk.

The problem is that if we do expose whether a user has enabled strict 2nd factor, a lot of 3rd parties will "force" users to become a "strict" 2 factor users without understanding what that means. So for now we don't have a timeline.

Sign up to request clarification or add additional context in comments.

6 Comments

Thank you very much for the quick response! I hope someday you give information on the severity of authorization in the account, not in GSuite.
@nvnagr Any change in this policy?
No official change but there has been more discussion and we would like to do this but there is no timeline.
@nvnagr, any changes?
@nvnagr Still no change? Would be really nice to get a bool, as suggested by arturgspb :)
|

Your Answer

By clicking “Post Your Answer”, you agree to our terms of service and acknowledge you have read our privacy policy.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.