I let my password expire on #myPay, the U.S. government's wage payment portal, and so it prompted me to change my password on my next login.
It prompted me after I entered my username and old password, but _before_ prompting me to enter my #MFA token.
Is this behavior correct?
#2FA #infosec #poll #FedLife
yes, password change before MFA is fine
3.2%
no, shouldn't be able to change passwd before MFA
96.8%
Poll ended at .