Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.


For more information on products and upcoming events around #dominoforever, please visit: HCL Domino Page


Status No Plans to Implement
Workspace Domino
Categories Security
Created by Guest
Created on Mar 27, 2025

Allow 2FA to use Email Only

We host systems that are used by customers who change companies all the time. Sometimes when they leave companies, we are not notified. Since people now take their BYOD phones with them, any MFA/2FA using SMS or Authenticator Apps can be used outside their company. This makes Domino's 2FA a security risk for us.

Since most companies cut off access to email upon termination, having 2FA able to be set to "ONLY Via Email" means that we can prevent users from starting at a new company and using their existing logins to our Domino platform to access data that is relevant to their old company.

  • Attach files
  • Guest
    Jul 21, 2026

    Really disappointing that you have to go to a third party, and pay additional fees, because HCL refuse to implement something that there is a clear business case for in many organisations that use Domino.

    Once again, a new feature that would be great if only HCL would take that final step.

  • Guest
    Jul 13, 2026

    Since this has been denied and we solved it long ago, I'll just let you know how we did it. We used a product called CYONE https://cyone.eu/products-and-solutions/two-factor-authentication/ It's happily running on our (currently) HCL Domino 14.5 FP1 Server and it has options to restrict to just email if needed.



    Regarding NIST compliance. The guest is correct to say that "NIST SP 800-63B, Section 5.1.3.1, prohibits the use of email as an out-of-band authenticator because it does not reliably prove possession of a specific device."

    However our threat model is primarily concerned with offboarding of our customers at other external institutions over which we have no control and are not notified. Our "Email Only" policy is a compensating control designed to leverage the fact that the only thing we can rely on those external institutions to do is to block email to users when they leave.

    In this era of BYOD devices, having a user-installed MFA app on their phone or using the phone's SMS - or even providing the user with a physical token is only effective if you have control over the user and knowledge that the user has left that place of employment.

  • Admin
    Thomas Hampel
    Jul 13, 2026

    2FA codes do not superseed propper user access control, e.g. by putting the user into an access deny/terminations group. So I'm sorry but I have to reject this idea.

  • Guest
    Feb 25, 2026

    FYI - NIST SP 800-63b prohibits the use of email for 2FA:

    https://pages.nist.gov/800-63-FAQ/#q-b11

    "Q-B11:

    Is the use of email acceptable in two-factor authentication?

    A-B11:

    NIST SP 800-63B does not allow the use of email as a channel for single or multi-factor authentication processes. This is specified in Section 5.1.3.1, Out-of-Band Authenticators:

    [Authentication] methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentication."

  • Guest
    Apr 3, 2025

    We have the same issue. Additionally, some of our clients are prevented from using their mobile phones on site at their work place so the emailing the code would be the only option.