To reset a user’s MFA, an administrator clears the enrollment on their identity platform so the user can register a new method: in Microsoft Entra ID and Microsoft 365 through Require re-register MFA in the Entra admin center, in Okta through Reset multifactor in the Admin Console, and in Duo by reactivating or re-enrolling the device. Each takes a minute or two.
The procedures below are well documented. The step none of them completes for you is the one before the reset: deciding whether the person asking is the account holder. Each of these vendors ships identity verification of its own, and the reset procedure itself still assumes that decision has already been made. That assumption is what attackers target.
Before the steps: what a reset actually does
Resetting MFA deletes an enrollment and opens a registration window behind it.
Microsoft’s documentation is specific about this. Require re-register MFA “deactivates the user’s hardware OATH tokens and deletes the following authentication methods from this user: phone numbers, Microsoft Authenticator apps and software OATH tokens,” after which “If needed, the user is requested to set up a new MFA authentication method the next time they sign in” (Microsoft Learn, retrieved 2026-08-18).
Okta describes the same shape: “Resetting MFA means that the user’s enrollment in their factors is canceled and they have to enroll in them again” (Okta Help, Classic Engine, retrieved 2026-08-18). Okta’s Identity Engine documentation words it as authenticators rather than factors, so check which publication matches your tenant. The action cannot be undone.
Duo’s warning covers the equivalent for its mobile credential: “Regenerating an activation code invalidates an existing activation! This will immediately invalidate any existing Duo Mobile credentials for that device” (Duo Administration documentation, retrieved 2026-08-18).
So for a short window after the reset, the account’s second factor is whatever the next person to complete registration says it is. If that person is not your employee, the reset has handed the account over rather than restored it.
Microsoft Entra ID and Microsoft 365
Entra ID and Microsoft 365 are administered from the same place, so the procedure is one procedure.
You need at least the Authentication Administrator role.
1. Sign in to the Microsoft Entra admin center. 2. Browse to Entra ID > Users. 3. Select the user, then select Authentication methods. 4. Choose the action you need:
- Require re-register MFA deletes the phone numbers, Authenticator app registrations, and software OATH tokens, and deactivates hardware OATH tokens.
- Reset password issues a temporary password the user must change at next sign-in.
- Revoke sessions invalidates refresh tokens, forcing reauthentication across active sessions and applications.
Revoke sessions is the step teams skip, and it is the one that closes the door. Resetting a factor without invalidating existing tokens leaves any session an attacker already established still working. If you are resetting because you suspect compromise rather than because someone lost a phone, revoke sessions as well.
Methods can also be managed through the Microsoft Graph PowerShell module Microsoft.Graph.Identity.Signins when you need this scripted.
Microsoft’s legacy MFA management experience in the admin center retired on 30 September 2025, so guidance written before that date may describe screens that no longer exist.
Okta
For a single user and specific factors:
1. In the Admin Console, go to Directory > People. 2. Open the user’s profile. 3. Select More Actions > Reset Multifactor. 4. Select the factors to reset. 5. Select Reset Selected Factors or Reset All, then confirm.
On Identity Engine the wording differs: the path is More Actions > Reset Authenticators and the button is Reset Selected Authenticators. If the menu item in your tenant does not say “Reset Multifactor,” you are on Identity Engine.
For several users at once on Classic Engine, go to Directory > People, select Reset multifactor, choose the users, and select Reset Multifactor Authentication. Okta does not publish an equivalent multi-user path on its Identity Engine page.
The action cannot be undone, and the user must enroll again before they can use MFA.
Duo
Duo separates the cases, which is useful when a device is lost rather than replaced.
- Reactivate Duo Mobile for a user whose device still exists: open the user’s details, find the phone in the Phones section, and select Reactivate Duo Mobile. You generate an activation code (24-hour default lifetime) and send instructions by SMS or email.
- Re-enroll by sending an enrollment email from the Device Enrollment section, or by generating an enrollment code and delivering the link and code to the user. Enrollment codes also expire 24 hours after generation by default.
- Bypass codes cover the interim. Select Add Bypass Code on the user’s properties page. The default expires after a single use or in 60 minutes, whichever happens first, and both values are adjustable.
Bypass codes deserve care. A long-lived, multi-use bypass code is a password that skips your second factor, and it tends to outlive the incident that justified it. Keep the defaults unless you have a specific reason not to.
Duo’s own documentation raises the identity question directly: “Before you or another admin in your organization makes a change at the request of a Duo user, like resetting a locked-out user back to ‘Active’ status, you may want to verify the user’s identity” (Duo Administration documentation, retrieved 2026-08-18).
The rest of this page is about that sentence. Note the phrasing: you may want to. The platform surfaces the decision and leaves it with you, which is the correct division of responsibility. It is also where the risk concentrates.
The reset is the request attackers make
None of the platforms above is weak here, and this is not a gap in any of them. The reset flow is doing exactly what it is designed to do: give an administrator a way to restore access for a legitimate user who has lost their factor. Each vendor also sells an identity verification product to sit in front of it. What the reset procedure itself assumes, in all of them, is that the identity decision has already been made somewhere else.
The trouble is that attackers have concentrated on precisely that decision.
CISA’s advisory on Scattered Spider records the group conducting “spearphising [sic] calls to convince IT help desk personnel to reset passwords and/or transfer MFA tokens,” and, in its July 2025 update, “Posed as employees to convince IT and/or helpdesk staff to provide sensitive information, reset the employee’s password, and transfer the employee’s MFA to a device they control …” (CISA, advisory AA23-320A). MITRE tracks the technique as Impersonation (T1656).
Mandiant found voice phishing involved in 23% of cloud intrusions, ranking first in that category, and 11% of intrusions overall (Mandiant, M-Trends 2026). Google Threat Intelligence documented UNC6671 targeting financial services with spoofed help desk numbers, tracing $10.69 million in ransoms (Google Threat Intelligence, August 2026).
The financial scale of what follows a successful intrusion is on the public record. MGM Resorts disclosed roughly $100 million in impact for the quarter after its 2023 incident (MGM Resorts, Form 8-K, October 2023). Caesars reported a payment of approximately $15 million (Caesars Entertainment, Form 8-K, September 2023). Marks & Spencer put its 2025 incident at around £300 million in operating profit (M&S trading statements, 2025).
The attacker’s pretext is the same sentence a genuinely locked-out employee uses, which is what makes it work: I can’t get my code, my phone is gone, I’m travelling, I need this today.
What “safely” requires
The reset procedure is the easy half. A safe reset has four properties, and none of them is a product setting.
Verify the human before you clear the factor, not after. Once the enrollment is deleted the window is open. Verification has to gate the action.
Verify against something the requester does not control. A voice is not evidence, because a recorded voice is a sample and samples can be reproduced. Knowledge questions fare no better; Microsoft’s own administrator reset policy prohibits security questions outright. This is a property of the method rather than of any platform, because every platform inherits it. Checking a government-issued ID against the authority that issued it, in the United States the state DMV over the AAMVA network, gives you a record the caller never touched.
Watch the number. A phone number that changed hands recently carries more weight than anything else on a reset call. SIM swap and port-out detection surfaces it from the carrier rather than from your directory. CISA lists SIM swap attacks among Scattered Spider’s core techniques.
Close the session, not just the factor. Revoke or invalidate existing sessions when the reset is prompted by suspicion. A new factor on an account an attacker is already inside solves nothing.
And one process rule that outranks all four: make the verification non-negotiable and measure how often it is skipped. Every reset flow has an escape hatch for when verification fails. If agents can talk themselves past it under pressure, your control covers only the calls nobody was pushing on.
When the request itself looks wrong
Some reset calls carry their own warning signs, and agents should have permission to act on them without needing to be certain.
The reset follows a burst of push prompts. CISA documents Scattered Spider sending “repeated MFA notification prompts leading to employees pressing the ‘Accept’ button (also known as MFA fatigue)” (CISA, advisory AA23-320A). A reset request arriving shortly after a wave of prompts to that account is a different conversation from a lost phone. Check the sign-in logs before you clear anything.
The number changed recently. A SIM swap or port-out shortly before a reset request is the strongest single signal available on these calls.
The urgency is doing the work. Genuine users are inconvenienced. The pressure to skip a step usually comes from the other side.
The request expands mid-call. A caller who starts with a password reset and moves on to MFA re-registration, a new device, or a mailbox forwarding rule is describing an account takeover in progress rather than a lockout.
Give agents a documented, blameless way to pause a reset and escalate. If the only options are approve or accuse a colleague of fraud, they will approve. And record the escalation, because the same account being reset repeatedly across a short window is a pattern that only shows up if someone is counting.
Where this leaves the help desk agent
The person making this decision is usually early in their career, measured on handle time and first-call resolution, and talking to someone who sounds confident and stressed. Asking them to detect a deepfake is not a control. It is a hope.
What works is giving them a result rather than a judgment: a check that returns red, yellow, or green, that runs inside the call, and that does not depend on the caller having enrolled anything beforehand, since “I can’t use my MFA” is the reason for the call.
ATO Protect runs that check in front of the reset. It verifies a government-issued ID against the issuing authority in real time, adds SIM swap and port-out detection and patented man-in-the-middle and anti-replay detection (US Pat. 10,601,859), and runs no selfie or liveness challenge, because generative AI defeats those. It needs no pre-registration, so it works for the caller who cannot reach any enrolled factor. Agents use it through a web portal with no integration work, and the ATOP API can run the same check inside your own workflow: it integrates with almost any system that allows it, including Microsoft Entra ID, Okta, and IVR platforms. Many teams run it alongside the platform they already have. See ATO Protect use cases and ATO Protect for IT Help Desk.
Frequently asked questions
How do I reset MFA for a user in Microsoft Entra ID or Microsoft 365? Sign in to the Microsoft Entra admin center as at least an Authentication Administrator, go to Entra ID > Users, select the user, then Authentication methods, and choose Require re-register MFA. This deactivates hardware OATH tokens and deletes the user’s phone numbers, Microsoft Authenticator registrations, and software OATH tokens. If needed, the user is asked to set up a new method at next sign-in.
How do I reset MFA for a user in Okta? In the Admin Console go to Directory > People, open the user, select More Actions > Reset Multifactor, choose the factors, and select Reset Selected Factors or Reset All. Confirm the action, which cannot be undone. The user must enroll again before they can use MFA. On Identity Engine the menu item is Reset Authenticators rather than Reset Multifactor.
How do I reset a user’s Duo device? Use Reactivate Duo Mobile from the user’s details page if the device still exists, or send an enrollment email or code to re-enroll. Activation and enrollment codes expire 24 hours after generation by default. Bypass codes cover the gap and default to expiring after a single use or in 60 minutes, whichever happens first.
Should I revoke sessions when I reset MFA? Yes, when the reset is prompted by suspected compromise. In Entra ID, Revoke sessions invalidates the user’s refresh tokens and forces reauthentication across active sessions and applications. Resetting a factor alone leaves an attacker’s established session working.
What is the risk in resetting MFA? The reset deletes the existing enrollment and opens a registration window. Whoever completes registration next controls the account’s second factor. If the requester was an impersonator, the reset hands them the account.
How should I verify someone before resetting their MFA? Verify against something the caller does not control, before clearing the factor. Neither a voice nor a knowledge answer is something the caller can be shown to uniquely control. Microsoft’s own administrator reset policy prohibits security questions outright. Verifying a government-issued ID against the issuing authority, together with SIM swap detection, checks records the caller cannot alter.
Do attackers really target MFA resets? Yes. CISA advisory AA23-320A documents Scattered Spider using calls to convince help desk personnel to reset passwords and transfer MFA tokens to a device the attacker controls.
Every platform on this page gives you a clean way to reset MFA in about a minute. Each of them also offers a way to verify identity: Entra ID’s account recovery with a third-party verification provider and Face Check, Okta’s document and liveness verification, Duo’s Persona-backed IDV. What those checks share is their shape. The caller presents a document and a face, and the result is matched against what is already in your directory. The questions worth asking are what the document gets checked against, and whether you want a live face in the loop at all.
ATO Protect answers the part no vendor documents: who is asking.