Require two-factor authentication for staff
One box in Administration → Configuration → Security: a staff member without 2FA on Discord can no longer enter the admin area or the MDT; the forum stays open.
Updated on Oct 5, 2026, 1:36 p.m.
In short. Agora does not generate six-digit codes: it reads what Discord says about the account at each sign-in. When the setting is on, a staff member whose Discord account has no 2FA is sent to Discord instead of entering the admin area or the MDT.
Who is affected #
- The
adminandmoderateurgroups. - Any member of a group that received a right (moderate, applications, department management).
- Designated reviewers and members of a recruitment rank: they are blocked by 2FA too (the rule is the same at sign-in, on the member's Security page, on their page and when you add a role).
- The admin area, moderation, the console and the MDT.
The forum stays open to everyone, 2FA or not.
Turn it on #
- First turn on 2FA on your own Discord account. The setting applies immediately: without it, you would lock yourself out.
- Administration → Configuration → Security.
- Tick Require Discord 2FA from staff.
- Save.
What your staff will see #
| Screen | Meaning | What to do |
|---|---|---|
| Your Discord account has no two-factor authentication | Discord said 2FA is missing | Turn it on in Discord, then sign in to the site again |
| Check still needed | Agora does not know yet (Discord only tells at sign-in), or what it said is more than 30 days old | Sign out, then sign in again with Discord |
| Check unavailable | The database did not answer | Reload the page in a moment |
Right after turning it on, all staff already signed in go through Check still needed once. That is normal.
Each of these screens offers a Sign in again with Discord button: it redoes the Discord sign-in and brings you straight back to My account → Security, without going through another menu. This button does not exist in the in-game tablet (Discord sign-in does not open there): administration is done in the browser.
See a staff member's state #
The member's page (Administration → Members) shows their Discord 2FA as seen at their last sign-in, for all accounts that 2FA blocks: groups with rights, designated reviewers and recruitment ranks included. You can thus see why a "Customs officer" stays out. After 30 days it says "to recheck" (the stale state is also shown on the member's own screen).
Good to know #
- What Discord said is valid for 30 days. After that, Agora treats the state as unknown: a 2FA removed on Discord in the meantime does not go unnoticed. The staff member sees the Check still needed screen again and only has to sign in with Discord.
- A txAdmin administrator who is only an ordinary Agora member also gets their 2FA recorded at sign-in, if their Discord ID is in the txAdmin account list that Agora reads.
- A member who was just promoted must sign in again once with Discord. When you add a role with + Add a role, the screen warns you ("the promoted member will have to sign in again (2FA)") for a group with rights or a power key as well as for the "staff" box.
- An active administrator who never signs in again sees the Check still needed screen every 30 days: that is intended, one click on Sign in again with Discord is enough.
- An unreadable state never grants access: the verdict falls back to "unknown".
- Every change of the setting is written to the administration log.
To help your staff turn on 2FA: Turn on Discord 2FA.
Was this article helpful?
Related articles
- Turn on two-factor authentication in Discord (staff)If your server requires it, turn on 2FA on your Discord account, then sign in to the site again: access to the MDT and the admin area comes back at once.
- Two-factor authentication refused or "Check still needed"A staff member blocked by 2FA: turn it on in Discord, sign in again, and check the state seen at their last sign-in.
- Groups and permissionsForum groups carry rights (moderate, review applications, manage an MDT department); MDT rights come from the in-game job.
- Errors and error reports (Administration → Errors)Agora stores every failure of the site, browsers and the FiveM resource, cleaned of any sensitive data, and can send it to the Agora team.