Skip to main content
Question

Security / Account security

  • September 29, 2026
  • 13 replies
  • 112 views

Forum|alt.badge.img

Are there any plans for increasing account security and adding mfa to authentication?

13 replies

Airgetlam
  • September 29, 2026

Why do you need Multi Factor Authorization to log in to your Sonos account? What data is being stored that you need to ‘protect’? 
 

For that matter, the only time you really need to ‘log in’ is when adding streaming choices, most playback is done with out logging in. 


User117655
Forum|alt.badge.img+10
  • Prodigy II
  • September 29, 2026

Why do you need Multi Factor Authorization to log in to your Sonos account? What data is being stored that you need to ‘protect’? 
 

For that matter, the only time you really need to ‘log in’ is when adding streaming choices, most playback is done with out logging in. 

I don't think it is at all unreasonable to expect tighter account security in this day and age. Regardless of the depth of data held. There is also the security of many potential automation integrations to consider.

I for one would welcome 2fa/mfa on the Sonos account(s)... +1 here ​@Paladin 👍


Stanley_4
  • Grand Maestro
  • September 29, 2026

Which account, store, forum, play or all three?

I could see it being an option for the store, since I don't store credit card info it would only be an aggravation for me.

For the forum it would really cut back my posting as I post from multiple devices and rarely have my phone handy to authenticate. 

The web app is frustrating enough as it doesn't remember logins, making it worse would be bad.

 

Edit, forgot the App, don't want the aggravation there either.


melvimbe
  • September 29, 2026

One issue with MFA, at least when access the web version or if it’s required for app control, is you could have multiple users, but only one user account.  I don’t think people want spouse kids pinging them to provide the 5 digit code every time they want to play music.  (My ‘kids’ already do this with Netflix).

If we are only talking about administration stuff, ok, but I mostly don’t care.


Forum|alt.badge.img
  • Author
  • Contributor I
  • September 29, 2026

All my devices are stored in my account, which contains data that I do not want to be accessible to bad actors. They can potentially get control over my devices and use the built in microphones on some devices to listen. If that is not enough then accessing my account, people can get access to use the upgrade device program to get rebates and disable my devices.

Security is a major concern, especially on these types of devices.


Forum|alt.badge.img
  • Author
  • Contributor I
  • September 29, 2026

One issue with MFA, at least when access the web version or if it’s required for app control, is you could have multiple users, but only one user account.  I don’t think people want spouse kids pinging them to provide the 5 digit code every time they want to play music.  (My ‘kids’ already do this with Netflix).

If we are only talking about administration stuff, ok, but I mostly don’t care.

It doesn’t have to be a forced option, just available to us that want the extra security.


Forum|alt.badge.img
  • Author
  • Contributor I
  • September 29, 2026

Which account, store, forum, play or all three?

I could see it being an option for the store, since I don't store credit card info it would only be an aggravation for me.

For the forum it would really cut back my posting as I post from multiple devices and rarely have my phone handy to authenticate. 

The web app is frustrating enough as it doesn't remember logins, making it worse would be bad.

 

Edit, forgot the App, don't want the aggravation there either.

All accounts should have this option, but it should be an option not forced.


Forum|alt.badge.img+18
  • Local Superstar
  • September 30, 2026

One issue with MFA, at least when access the web version or if it’s required for app control, is you could have multiple users, but only one user account.

MFA can be enabled for the first login a new device, if the user specifies the device is trusted.

I would personally like to see option of multiple ‘family’ Sonos logins and where the emails addresses can optionally be linked to Apple/Google, same as the vast majority of modern Apps.

https://support.apple.com/en-gb/102571

https://developers.google.com/identity/siwg

 

 


controlav
Forum|alt.badge.img+24
  • Lead Maestro
  • September 30, 2026

Why do you need Multi Factor Authorization to log in to your Sonos account? What data is being stored that you need to ‘protect’? 
 

For that matter, the only time you really need to ‘log in’ is when adding streaming choices, most playback is done with out logging in. 

Your entire system would be exposed to the internet if your Sonos credentials leak, via the web player. If you enjoy random audio be played in the night, then you have no need to be concerned about the low level of account security. If you want others posting on this account using your name, then don’t be concerned with this either.


User117655
Forum|alt.badge.img+10
  • Prodigy II
  • September 30, 2026

Seen this so many times before, the 'I don't want the inconvenience of mfa' view… then details get stolen.

Name, address, email address, profile, maybe favoured password pattern. Associated accounts then get hit across the board, phishing mails and potentially way worse!

It is at that point the real meaning of inconvenience hits home...


Forum|alt.badge.img+18
  • Local Superstar
  • September 30, 2026

MFA does not have to be implemented in an inconvenient way. Anyone who uses Apple Pay or similar will find it very convenient.


Forum|alt.badge.img
  • Author
  • Contributor I
  • September 30, 2026

I have created a support case with Sonos and they promised to escalate it. Hope it helps a little bit at least to get the process started.


Forum|alt.badge.img+18
  • Local Superstar
  • September 30, 2026

Déjà vu ?

Has been raised as feature request 2 and a bit years ago, when play.sonos.com was launched.

In theory we are 2 and a bit years closer to a solution, than we were 2 and a bit years go 😀