<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR000029ymZu0AIOkta Classic EngineMulti-Factor AuthenticationAnswered2026-09-21T15:40:50.000Z2026-09-21T09:21:51.000Z2026-09-21T15:40:50.000Z

DavidK.80434 (Customer) asked a question.

Users need to re-enrol in OKTA, 2FA is not working

Some of our users have lost or signed out of their Okta 2FA apps and are having difficulty setting it up again.

I'm not sure of the correct process. I go to Admin, then directory, select the user. There I have the option to reset the authenticator and reset/remove the password, but I don;t actually know what happens on the user's side when I do this.

Will either or both of these trigger enrolment of their device again?

 

Thanks,

David Kernaghan


  • Paul S. (Okta, Inc.)

    Hello @DavidK.80434 (Customer)​ Thank you for posting on our Community page!

     

    You are asking what happens to your users when you click the "Reset Authenticator" button versus the "Reset Password" button in the Okta Admin Console, and whether either action triggers re-enrollment of their Multi-Factor Authentication (MFA) device.

     

    Solution: These are two separate actions with different effects. Resetting the authenticator is the correct action for users who have lost or signed out of their 2FA app; resetting the password is not required and serves a different purpose.

     

    Reset Authenticator — this is what you need:

    1. Navigate to Admin Console → Directory → Users.
    2. Select the affected user.
    3. Click "More Actions" (or the three-dot menu).
    4. Select "Reset Authenticator."
    5. Confirm the action.

     

    When you reset the authenticator, the user's enrolled MFA factors (such as Okta Verify, Google Authenticator, or other 2FA apps) are cleared from their account. On the user's next login attempt, they will be prompted to re-enroll their MFA device. They can then install the app on their new or recovered device and complete the enrollment flow, scanning a QR code or entering a setup key to link the app to their account.

     

    Reset Password — this is separate and optional:

    Resetting the password clears the user's password and forces them to set a new one on their next login. This is not required for 2FA re-enrollment and should only be used if you also want to force a password change. If the user still remembers their password, you do not need to reset it.

     

    Do not reset both unless you have a specific reason to do so. Resetting only the authenticator is sufficient to allow users to re-enroll their 2FA app on a new device.

    After you reset the authenticator, communicate with the affected users so they know to expect the re-enrollment prompt at their next login. They should have their new device ready with the Okta Verify app (or whichever 2FA app your organization uses) already installed.

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    • DavidK.80434 (Customer)

      Thank you for responding Paul.
      What would happen to the users is I had already pressed both?

      Thanks,
      David Kernaghan
      • Paul S. (Okta, Inc.)

        Hello @DavidK.80434 (Customer)​  They will have to setup a new MFA and a new Password. Nothing bad in particular, maybe more of a nuisance as they will need to setup a new password for the Okta account, even though they had one they new.

Loading
Users need to re-enrol in OKTA, 2FA is not working