<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00006sQTIrCAOOkta Classic EngineAdministrationAnswered2026-04-01T09:00:20.000Z2021-03-12T15:12:59.000Z2021-03-17T13:43:52.000Z
  • john.grable1.5639397627953508E12 (Mission Critical Technical Support Engineering)

    Hi Umang,

     

    There is actually another discussion which covers this scenario. You can find it by following this link but I'll provide the answer below as well. https://support.okta.com/help/s/question/0D50Z00008C3jkz/self-service-for-mfa-reset?language=en_US

     

    "The Okta Admin would have to reset the user's MFA since the user needs their "lost" device to authenticate into Okta to reset their MFA, which I would happen after the user has replaced the lost device with a new one. Another option would be for the user to authenticate into Okta from a location which does not require MFA, and then reset the MFA option manually from the Settings window."

     

    Expand Post
  • k5fuw (k5fuw)

    If Okta Verify is the only MFA factor in which the user is enrolled and the user loses access to the enrolled device, the only option is to have an administrator reset that factor for them.

     

    The ability to authenticate into Okta without MFA is not a solution. Once a user has enrolled in any MFA factor, Okta will prompt that user for MFA any time the user attempts to Edit their Okta profile, thus preventing the user from resetting the lost MFA-enrolled device themselves. Once the admin has reset the lost MFA factor, the user will again be able to Edit their Okta profile without being prompted for MFA.

     

    The best advice you can give your users is to enroll multiple MFA factors, preferably on different devices or platforms (for example, enrolling in Okta Verify and Google Authenticator on the same phone is pointless if you lose access to that device), so that the loss of one MFA-enrolled device does not prevent the user from accessing Okta, their applications, or their profile.

     

    Expand Post
This question is closed.
Loading
Okta verify self service- How users can be verified before resetting Okta verify MFA