How QCUI Handles the Target User's MFA Requirement

How QCUI Handles the Target User's MFA Requirement describes a current QCUI 1.0.03 implementation detail that matters when you are validating security, session isolation, or support behavior.

Explicit support-session treatment

After all QCUI authorization and target checks pass, the forked frontend session sets com_users.mfa_checked to 1. This prevents the impersonating Super User from being sent through the target user’s MFA challenge.

Why this is not an MFA bypass for normal login

The path is available only after an authenticated Super User initiates a short-lived one-time handoff for an eligible non-Super-User target. It does not change the target’s MFA configuration or credentials.

End cleanup

When impersonation ends, QCUI resets the MFA marker to 0 as it returns the frontend session to guest.

Security boundary

The controls described for How QCUI Handles the Target User's MFA Requirement are complementary. Super-User authorization does not make a reusable token safe; a one-time token does not make Shared Sessions safe; and a visible banner does not make state-changing customer actions harmless. Preserve the complete 1.0.03 security model rather than removing individual checks for convenience.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.