This article is best for:
Admins 👩💻👨🏾💻
All Account Types 💼
In this article:
Why users get locked out of MFA
What you can do as an admin
How to request an MFA reset from Bonusly Support
Preventing future lockouts
Why users get locked out of MFA
Multi-factor authentication (MFA) adds an important layer of security to your Bonusly account. But sometimes people lose access to the authenticator app that generates their login codes. This can happen when someone:
Gets a new phone and doesn't transfer their authenticator app
Accidentally deletes their authenticator app
Loses or resets their device
Misses the MFA setup deadline after your company enables required MFA
When this happens, the user can't log into Bonusly—even with the correct password.
What you can do as an admin
If you're a **company admin** with MFA enabled on your own account, you can reset MFA for a locked-out teammate yourself directly from **Account settings → Security**. No support request needed. Once you reset it, the user sets up MFA again the next time they sign in.
What you CAN do:
Reset a user's MFA yourself from Account settings → Security, for up to 5 users at a time. See the steps below.
Temporarily disable company-wide MFA** only if the admin needs to restore access immediately, and you re-enable it right after.
❗️Important: Disabling company-wide MFA affects everyone, not just the locked-out user. Resetting the individual user's MFA is almost always the better option.
Settings
A few limits to know
You need MFA enabled on your own account first. You confirm each reset with a code from your own authenticator app.
You can reset MFA only for people in your own company, and only for users who currently have MFA set up.
You can't reset your own MFA here (use your personal **Security** settings), and you can't reset another admin's MFA.
Deactivated users can't be reset.
How to reset a user's MFA
Go to **Account settings → Security** (click your user avatar in the bottom-left menu → **Manage admin settings** → **Account settings**, then scroll down to **Security**).
Find the **Reset user MFA** section.
Search for and select the locked-out user by name. You can select up to 5 users at once. (Users who don't currently have MFA enabled can't be selected.
Click **Reset MFA**.
In the confirmation window, enter the current 6-digit code from **your own** authenticator app, then click **Reset MFA** to confirm.
What happens next
The selected users' MFA is cleared right away, and they're signed out of any active sessions.
Each user gets an email letting them know their MFA was reset.
The next time they sign in, they'll set up MFA fresh with their authenticator app.
💡 **Tip:** For security, resets are limited to about one per minute, if you're clearing several people, the button pauses briefly between resets.
When to contact Bonusly Support
Resetting MFA yourself covers almost every lockout. Reach out to Support only when you can't do it in-product — for example
You're the only admin and you're the one locked out.** No one else can reset your MFA, so contact Support.
Something isn't working as expected.
To request an MFA reset from Support, email us at [email protected]
FAQs
Can I reset MFA for just one user?
Yes. A company admin can reset MFA for individual users (up to 5 at a time) from **Account settings → Security**. You can't turn MFA off for a single user while it stays required for everyone else. MFA is required or optional at the company level but resetting lets a locked-out user re-enroll.
How long does an MFA reset take?
If you reset it yourself from Account settings → Security, it takes effect immediately, and the user is notified by email. If you email Support instead, most requests are handled within support hours (9am – 9pm ET)
Will the user lose any data when their MFA is reset?
No. Resetting MFA only clears their authentication setup—their points, history, and account settings stay intact.
What if I need to restore access immediately?
Reset the affected user's MFA yourself from **Account settings → Security** It's immediate. Temporarily disabling company-wide MFA also works, but it lowers security for everyone, so reset the individual user instead whenever you can.
Can users disable their own MFA?
Only if your company doesn't require MFA. If MFA is required company-wide, users can't disable it themselves—which is by design for security.
Questions? Send us a note to [email protected]; we'd be happy to help!
Was this article helpful? Let us know by rating it below with an emoji and sharing your feedback!
