Airlock 2FA Device Cleanup Task
Task that deletes long-unused Airlock 2FA devices via the Futurae Admin API.
Each run downloads the complete list of enrolled devices of the Futurae service and applies up to three cleanup rules per account. Each rule is enabled by configuring its period:
- 'Maximum Age of Never-Used Devices' deletes devices that were never used after enrollment.
- 'Maximum Inactivity Period' deletes devices after long inactivity, even an account's only device.
- 'Multi-Device Inactivity Period' deletes inactive devices while keeping the account's most recently used device.
Only devices of the types selected in 'Device Types in Scope' are deleted. Deletions are reported to the user trail of the linked IAM user.
Note: The rules are evaluated on the device inventory downloaded at the start of the run: device usage occurring while the task runs may not be considered.
Note: Futurae records the last use of a device only since May 19, 2026. Usage before this date is invisible to this task: a device last used before this date counts as never used. It is ignored by the inactivity rules and deleted by 'Maximum Age of Never-Used Devices' if its enrollment is old enough.
Typical use cases:
- Delete all devices that were not used within one year: set 'Maximum Inactivity Period' and 'Maximum Age of Never-Used Devices' to 365d.
- Delete all devices that were not used within one year since their last use, and delete devices that were enrolled but never used after one month: set 'Maximum Inactivity Period' to 365d and 'Maximum Age of Never-Used Devices' to 30d.
airlock2faSettings) maxAgeOfNeverUsedDevices) Deletes never-used devices: a device is deleted if it was enrolled longer ago than this period and was never used.
If not configured, never-used devices are kept forever because the other properties ignore never-used devices.
Must be longer than the 'Cooldown Period' of the Airlock 2FA settings (if it is configured). Otherwise, devices can be deleted before their cooldown ends, so before they can be used at all.
Note: Futurae records device usage only since May 19, 2026. Devices whose last use predates this date count as never used. All such devices are deleted if they were enrolled longer ago than this period, even though in reality they are not never-used.
The duration must be specified in the format "2d 4h 10m 5s" (any part can be omitted).
maxInactivityPeriod) Deletes inactive devices that were used at least once: a device is deleted if it was last used longer ago than this period. This also deletes an account's only or most recently used device.
This rule ignores devices that were never used.
If not configured, an account's most recently used device is kept forever.
Note: Inactivity is measured against usage recorded by Futurae since May 19, 2026. Devices whose last use predates this date count as never used and are ignored by this rule. Devices without recorded use are only handled by 'Maximum Age of Never-Used Devices'.
The duration must be specified in the format "2d 4h 10m 5s" (any part can be omitted).
multiDeviceInactivityPeriod) Deletes inactive devices used at least once: a device is deleted if it was last used longer ago than this period. The account's most recently used device is kept.
This rule ignores devices that were never used.
If not configured, inactive devices are only deleted by 'Maximum Inactivity Period'.
Must be shorter than 'Maximum Inactivity Period' (if it is configured). Otherwise, this rule has no effect because such devices are already deleted by 'Maximum Inactivity Period'.
Note: Inactivity is measured against usage recorded by Futurae since May 19, 2026. Devices whose last use predates this date count as never used and are ignored by this rule. Devices without recorded use are only handled by 'Maximum Age of Never-Used Devices'.
The duration must be specified in the format "2d 4h 10m 5s" (any part can be omitted).
deviceTypesInScope) The device types considered for cleanup. Devices of other types are never deleted.
An account only counts as having no devices left if all of its devices, including those of other types, are gone.
deleteAccountWhenNoDevicesRemain) If enabled, an Airlock 2FA account is deleted in case the cleanup has removed its last device.
Warning: The deletion of a Futurae account is permanent and irreversible. When the user enrolls a new device afterwards, a new Futurae account is created.
dryRun) If enabled, the task only logs which devices and accounts it would delete, without deleting anything.
Use this to validate that the configured periods result in the expected set of deleted devices.
type: Airlock2FADeviceCleanupTask
id: Airlock2FADeviceCleanupTask-xxxxxx
displayName:
comment:
properties:
airlock2faSettings:
deleteAccountWhenNoDevicesRemain: false
deviceTypesInScope: [Mobile App]
dryRun: false
maxAgeOfNeverUsedDevices:
maxInactivityPeriod:
multiDeviceInactivityPeriod: