3
How do you administratively reset 2FA?
Question asked by A System Administrator - 11/2/2021 at 12:30 PM
Answered
I'd like to set our domain to "Force" 2FA but before I do so I've been using a test domain to see how the workflow actually goes.

I know users will do things like replace/lose their phone so I wanted to verify there is a method to reset 2FA on an administrative level. Looking around on the user property page (as primary admin) I'm not seeing any way to do that though...

Am I missing something?

8 Replies

Reply to Thread
0
Kyle Kerst Replied
Employee Post
Good afternoon, I hope you're doing well today. In our latest public release there is a Disable button for the 2FA functionality when impersonating the user account, so you could use this to turn off 2FA for the user so that they can get set up on their new device: 
So, you will need to impersonate to see the option, but once inside the user's account you can quickly turn it off from there. I hope this helps! :-)
Kyle Kerst System/Network Administrator SmarterTools Inc. (877) 357-6278 www.smartertools.com
0
That's odd.. I have the latest release available on the website installed (Enterprise Build 7957) but this is what I see when I impersonate someone with 2FA enabled:


Is there another build available I'm not seeing?
0
Stefano Replied
For what's it's written there, you should note impersonate the user but you've to login as that user.
0
Kyle Kerst Replied
Employee Post
That is very interesting. I checked on a couple of different servers running various versions including our current public branch and was able to find this option present in each account while impersonating. What browser are you impersonating from?
Kyle Kerst System/Network Administrator SmarterTools Inc. (877) 357-6278 www.smartertools.com
0
Hi Kyle,

I've tried in Chrome x64 (95.0.4638.69) and Firefox x64 (94.0.1)

Can you check the domain setting for the accounts you were testing and see if Two-Step Authentication is set to "Forced"? I'll think that might be why I'm not seeing an option to disable it but you are.

To be clear, I don't really want to disable 2FA; just have some way to reset it for a specific user so they can go through the re-enrollment setup again. Either via the nice enrollment wizard you see when the user first logs in or via some administrative method would be perfectly fine.
0
Not five minutes after that last post I figured out what my issue was...

The user I was testing with had not actually completed the "first login" wizard to enroll in 2FA yet so there wasn't anything to reset. I mistakenly thought I would see the controls for reset/disable no matter the status of the account but you only see the option to reset if 2FA is actually enabled (which makes sense...)

Here is what I see now:

Thanks for the help Kyle!
0
Kyle Kerst Replied
Employee Post
That makes sense, good find! You're very welcome!
Kyle Kerst System/Network Administrator SmarterTools Inc. (877) 357-6278 www.smartertools.com
0
kelsien mikein Replied
Awesome.

Reply to Thread