Skip to main content

What to do when a user is locked out of MFA

Help a team member regain access when they've lost their authenticator app or can't complete MFA.


This article is best for:

  • Admins 👩‍💻👨🏾‍💻

  • All Account Types 💼

In this article:

  • Why users get locked out of MFA

  • What you can do as an admin

  • How to request an MFA reset from Bonusly Support

  • Preventing future lockouts


Why users get locked out of MFA

Multi-factor authentication (MFA) adds an important layer of security to your Bonusly account. But sometimes people lose access to the authenticator app that generates their login codes. This can happen when someone:

  • Gets a new phone and doesn't transfer their authenticator app

  • Accidentally deletes their authenticator app

  • Loses or resets their device

  • Misses the MFA setup deadline after your company enables required MFA

When this happens, the user can't log into Bonusly—even with the correct password.


What you can do as an admin

If you're a **company admin** with MFA enabled on your own account, you can reset MFA for a locked-out teammate yourself directly from **Account settings → Security**. No support request needed. Once you reset it, the user sets up MFA again the next time they sign in.

What you CAN do:

  • Reset a user's MFA yourself from Account settings → Security, for up to 5 users at a time. See the steps below.

  • Temporarily disable company-wide MFA** only if the admin needs to restore access immediately, and you re-enable it right after.

❗️Important: Disabling company-wide MFA affects everyone, not just the locked-out user. Resetting the individual user's MFA is almost always the better option.

Settings

A few limits to know

  • You need MFA enabled on your own account first. You confirm each reset with a code from your own authenticator app.

  • You can reset MFA only for people in your own company, and only for users who currently have MFA set up.

  • You can't reset your own MFA here (use your personal **Security** settings), and you can't reset another admin's MFA.

  • Deactivated users can't be reset.


How to reset a user's MFA

  1. Go to **Account settings → Security** (click your user avatar in the bottom-left menu → **Manage admin settings** → **Account settings**, then scroll down to **Security**).

  2. Find the **Reset user MFA** section.

  3. Search for and select the locked-out user by name. You can select up to 5 users at once. (Users who don't currently have MFA enabled can't be selected.

  4. Click **Reset MFA**.

  5. In the confirmation window, enter the current 6-digit code from **your own** authenticator app, then click **Reset MFA** to confirm.

What happens next

  • The selected users' MFA is cleared right away, and they're signed out of any active sessions.

  • Each user gets an email letting them know their MFA was reset.

  • The next time they sign in, they'll set up MFA fresh with their authenticator app.

💡 **Tip:** For security, resets are limited to about one per minute, if you're clearing several people, the button pauses briefly between resets.


When to contact Bonusly Support

Resetting MFA yourself covers almost every lockout. Reach out to Support only when you can't do it in-product — for example

  • You're the only admin and you're the one locked out.** No one else can reset your MFA, so contact Support.

  • Something isn't working as expected.

  • To request an MFA reset from Support, email us at [email protected]


FAQs

Can I reset MFA for just one user?

Yes. A company admin can reset MFA for individual users (up to 5 at a time) from **Account settings → Security**. You can't turn MFA off for a single user while it stays required for everyone else. MFA is required or optional at the company level but resetting lets a locked-out user re-enroll.

How long does an MFA reset take?

If you reset it yourself from Account settings → Security, it takes effect immediately, and the user is notified by email. If you email Support instead, most requests are handled within support hours (9am – 9pm ET)

Will the user lose any data when their MFA is reset?

No. Resetting MFA only clears their authentication setup—their points, history, and account settings stay intact.

What if I need to restore access immediately?

Reset the affected user's MFA yourself from **Account settings → Security** It's immediate. Temporarily disabling company-wide MFA also works, but it lowers security for everyone, so reset the individual user instead whenever you can.

Can users disable their own MFA?

Only if your company doesn't require MFA. If MFA is required company-wide, users can't disable it themselves—which is by design for security.


Questions? Send us a note to [email protected]; we'd be happy to help!

Was this article helpful? Let us know by rating it below with an emoji and sharing your feedback!

Did this answer your question?