
00u1h01oyauCII8QF0h1.5541808600160776E12 (Customer) asked a question.
Okta verify self service- How users can be verified before resetting Okta verify MFA
Okta verify self-service- How users can be verified before they reset Okta verify MFA through self service, if they don't have old device with them.

Hi Umang,
There is actually another discussion which covers this scenario. You can find it by following this link but I'll provide the answer below as well. https://support.okta.com/help/s/question/0D50Z00008C3jkz/self-service-for-mfa-reset?language=en_US
"The Okta Admin would have to reset the user's MFA since the user needs their "lost" device to authenticate into Okta to reset their MFA, which I would happen after the user has replaced the lost device with a new one. Another option would be for the user to authenticate into Okta from a location which does not require MFA, and then reset the MFA option manually from the Settings window."
If Okta Verify is the only MFA factor in which the user is enrolled and the user loses access to the enrolled device, the only option is to have an administrator reset that factor for them.
The ability to authenticate into Okta without MFA is not a solution. Once a user has enrolled in any MFA factor, Okta will prompt that user for MFA any time the user attempts to Edit their Okta profile, thus preventing the user from resetting the lost MFA-enrolled device themselves. Once the admin has reset the lost MFA factor, the user will again be able to Edit their Okta profile without being prompted for MFA.
The best advice you can give your users is to enroll multiple MFA factors, preferably on different devices or platforms (for example, enrolling in Okta Verify and Google Authenticator on the same phone is pointless if you lose access to that device), so that the loss of one MFA-enrolled device does not prevent the user from accessing Okta, their applications, or their profile.