Account security
The Security section shows the effective protection state of the selected master account: email confirmation, enrolled two-factor methods, recovery codes, and passkeys.
Review order
- Verify the email address and its confirmation state.
- Check which 2FA methods are actually enabled.
- Review active and already disabled passkeys.
- Compare the request with sessions, IP activity, and the activity timeline.
- Reset protection only after completing the accepted owner-verification procedure.
Password and recovery
Changing a password and sending account recovery are separate operations. An administrative change sets a new value and requires a reason; recovery sends the standard player flow without exposing a new password to the operator.
PIN and sign-in protection
The PIN can be replaced or cleared. Clearing requires a separate confirmation because it removes an active protection factor. Shield state has its own form and is not a substitute for changing the password.
2FA and passkeys
Disabling one 2FA method does not affect the others. A full reset removes every active method and recovery code and is reserved for account recovery. Revoking a passkey prevents future sign-ins with that key while retaining its record and disabled date.
Passkey revocation, 2FA reset, and session termination require a reason. After confirmation, the updated state appears in the same table.
Do not disable protection only to bypass a sign-in error. Review account status, recent sessions, and account-takeover signals first.