=== Role Enforcement for Two Factor ===
Contributors: cliencedigital
Tags: 2fa, two-factor, two factor authentication, user roles, security
Requires at least: 7.0
Tested up to: 7.1.2
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Require two-factor authentication for selected user roles. An add-on for the Two Factor plugin.

== Description ==

Role Enforcement for Two Factor makes two-factor authentication mandatory for the user roles you choose. It's an add-on for the [Two Factor](https://wordpress.org/plugins/two-factor/) plugin, which provides the two-factor methods.

When a user in a selected role hasn't set up any two-factor method:

* After logging in, they're sent to their profile instead of the page they asked for.
* Any other dashboard page sends them back to their profile, where a notice and a dialog explain what to do.
* Once they set up at least one method, the dashboard works as usual.

Users in other roles aren't affected, and nothing is enforced until you select at least one role.

Enforcement applies to the dashboard only. It doesn't restrict the front end of the site.

The plugin makes no external requests and collects no data.

== Installation ==

1. Install and activate the [Two Factor](https://wordpress.org/plugins/two-factor/) plugin.
2. Install and activate Role Enforcement for Two Factor.
3. Go to Settings > Role Enforcement for Two Factor, select the roles that must use two-factor authentication, and save.

== Frequently Asked Questions ==

= Which roles are enforced after activation? =

None. Nothing changes until you select roles in the settings.

= Can I lock myself out? =

No. Users in a selected role can always reach their profile to set up two-factor authentication, administrators included.

= What happens if the Two Factor plugin isn't active? =

Enforcement is paused, and the settings page shows a warning. WordPress doesn't let you deactivate Two Factor while this plugin is active, so this only happens if Two Factor is removed another way, for example by deleting its folder.

= What happens to the settings when I delete the plugin? =

They're removed from the database.

== Changelog ==

= 1.0.0 =
* First release.
