Page MenuHomePhabricator

Enforce 2FA for all users on private wikis in WMF production
Open, In Progress, MediumPublic

Description

Once the technical capability exists (T420792), we should require all users on private wikis to have 2FA.

  • Phase 1: inactive private wikis (late June 2026)
    • advisorswiki
    • auditcomwiki
    • boardgovcomwiki
    • chairwiki
    • ecwikimedia
    • execwiki
    • fdcwiki
    • grantswiki
    • iegcomwiki
    • ilwikimedia
    • internalwiki
    • movementroleswiki
    • noboard_chapterswikimedia
    • projectcomwiki
    • searchcomwiki
    • spcomwiki
    • transitionteamwiki
    • wg_enwiki
  • Phase 2: WMF-internal wikis (time TBD)
    • collabwiki
    • legalteamwiki
    • officewiki
  • ...other phases TBD
    • arbcom_cswiki
    • arbcom_dewiki
    • arbcom_enwiki
    • arbcom_fiwiki
    • arbcom_itwiki
    • arbcom_nlwiki
    • arbcom_plwiki
    • arbcom_ruwiki
    • arbcom_zhwiki
    • boardwiki
    • chapcomwiki
    • checkuserwiki
    • conductwiki
    • electcomwiki
    • id_internalwikimedia
    • ombudsmenwiki
    • otrs_wikiwiki
    • stewardwiki
    • sysop_itwiki
    • sysop_plwiki
    • techconductwiki
    • u4cwiki
    • wikimaniateamwiki

Related Objects

Event Timeline

JJMC89 changed the task status from Open to Stalled.Wed, Jun 3, 10:39 PM
sbassett changed the task status from Stalled to In Progress.Tue, Jun 9, 4:37 PM
sbassett triaged this task as Medium priority.
sbassett moved this task from Incoming to In Progress on the Security-Team board.
sbassett added a project: SecTeam-Processed.
sbassett changed the status of subtask T428104: Notify users on phase 1 private wikis that 2FA enforcement is coming from Open to In Progress.

Change #1299644 had a related patch set uploaded (by Reedy; author: Reedy):

[operations/mediawiki-config@master] Set $wmgOATHAuthRequire2FAForAll = true for various private wikis

https://gerrit.wikimedia.org/r/1299644

Change #1299645 had a related patch set uploaded (by Reedy; author: Reedy):

[operations/mediawiki-config@master] Set $wmgOATHAuthRequire2FAForAll = true for all private wikis

https://gerrit.wikimedia.org/r/1299645