<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Self-Service Multi-Factor Authentication Reset Unavailable for Locked Out Okta End Users

Okta Classic Engine
Multi-Factor Authentication
Okta Identity Engine

Overview

End users cannot reset Multi-Factor Authentication (MFA) when locked out of an account because Okta restricts self-service resets for inaccessible accounts to prevent security risks. Administrators must reset the authenticators from the Admin Console, or the end user must sign in with a backup MFA method to remove the old factor.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Multi-Factor Authentication (MFA)
  • Self-Service
  • Application Programming Interface (API)

Cause

Okta prevents end users from resetting MFA configurations without account access to mitigate security risks and prevent unauthorized access by malicious actors. Consequently, only administrators possess the permissions to reset MFA for locked-out accounts.

Solution

How does an administrator reset Multi-Factor Authentication for an end user?

Review the video demonstration to observe the process of resetting MFA for a specific end user in the Okta Admin Console.

 

 

An administrator resets the authenticators for a specific end user from the Okta Admin Console by using the following steps:

  1. In the Okta Admin Console, navigate to Directory > People.
  2. Locate and select the specific user.
  3. Select More Actions in the top right area of the user profile.
  4. Select Reset Authenticators (or Reset Multifactor in Okta Classic Engine).
  5. Choose the specific factors to reset from the displayed list.

 

Okta prompts the end user to re-enroll in the MFA policy during the next login attempt. Okta does not enforce a time limit for re-enrollment.

 

How do administrators perform factor operations using the Okta API?

Leverage the Okta Factors API to reset user factors and set up custom automations for factor enrollment or resets.

 

 

How does an end user replace an old Multi-Factor Authentication method using a backup method?

If the user has access to a backup MFA method, they can go to their settings and remove the old MFA method. Review the related references for more information on user settings.

 

Related References

Loading
Okta Support - Self-Service Multi-Factor Authentication Reset Unavailable for Locked Out Okta End Users