This guide explains how an admin can reset Multi Factor Authentication (MFA) for a user, so they can set it up again on a new phone or authenticator app.
When to reset a user's MFA
Reset a user's MFA when they can no longer get a code from their authenticator app. For example, they have:
- lost or replaced their phone
- deleted or reinstalled their authenticator app
- removed the StoreFeeder entry from their authenticator app
- the MFA isn't working as expected
Resetting MFA does not change the user's password or permissions. It only clears their MFA set-up, so they are asked to scan a new QR code the next time they log in.
Before you start
- You must be an admin user. If you are not an admin, ask an admin on your account to do this for you.
- The user must already have MFA set up. If they haven't, the reset option isn't shown because there is nothing to reset.
Step 1: Open the user's settings
- Go to Settings > Company > Users.
- Find the user and click Edit/View User (or click their email address).
Step 2: Reset their Multi Factor Authentication
- On the Basic Settings tab, scroll down to the Security section.
- Next to Reset This User's Multi Factor Authentication, click Reset.
- StoreFeeder asks you to confirm: "Are you sure you want to reset multi factor authentication for this user? All saved devices will be removed and the user will have to relink their device." Click OK.
When it has worked, you'll see the message "This user's Multi Factor Authentication data has been reset", and the user's Trusted Devices list will be empty.
Step 3: Ask the user to set up MFA again
Let the user know their MFA has been reset. They should:
- Delete the old StoreFeeder entry from their authenticator app, if it is still there. The codes it shows will no longer work.
- Log in to StoreFeeder with their email address and password as usual.
- Scan the QR code shown on screen with their authenticator app (for example Google Authenticator, Microsoft Authenticator or Authy).
- Enter the 6-digit code from the app in the Verification Code box and submit it.
They can tick Remember this device for 30 days so they don't need a code on that device again for 30 days.
Troubleshooting
I can't see the Reset button
Either you are not an admin user, or this user hasn't set up MFA yet. Check the user's email address is correct, and ask an admin to try if you are not one.
"There was an error while attempting to reset this time based password authorisation"
The reset didn't complete. Refresh the page and try again. If it keeps happening, contact support.
The user still can't log in after the reset
Make sure they are scanning the new QR code, not using the old StoreFeeder entry in their app. Also check their phone's date and time are set automatically — authenticator codes are time-based, so if the phone's clock is wrong, its codes will be rejected.
Comments
0 comments
Please sign in to leave a comment.