When someone loses the device that generates their sign-in codes, they can be locked out of Pyron and unable to get back in on their own. As an administrator, you can clear the multi-factor devices on their account so they can set up a fresh one and sign in again.
When to reset
Reset a person's multi-factor devices when they cannot finish the second step of signing in and can't fix it themselves. The usual causes are a replaced or lost phone that held their authenticator app, a misplaced security key, or a lost email address or phone number that received their codes.
A reset removes every device on the account at the same time, so keep it for people who are properly stuck. Anyone who can still reach their account can add or remove their own devices from their profile security settings — point them there first when they only want to switch to a different method.
If the person will get their device back shortly — a phone left at home, say — you can hand them a single-use bypass code rather than wiping their devices. A bypass code clears the second step one time and expires after 24 hours, which gets them working again without setting everything up from scratch.
A reset clears the devices; it does not change whether your organisation asks for a second factor. Where multi-factor is enforced, the person is guided to set up a new device the next time they sign in — the reset lands them on that setup step, not straight into the app. Which factors they can choose from depends on the methods your organisation allows.
Resetting a device
You reset multi-factor devices from the same list where you manage everyone in your organisation — see Managing users. Each person's row in Setup carries a short set of quick actions, one of which resets their multi-factor devices.
- Open the users list in Setup.
- Find the person who is locked out. Match on their name or email.
- On their row, choose the action that resets their multi-factor devices.
- Confirm when you are asked — the reset cannot be undone.
Confirming removes every factor enrolled on that account: the authenticator app, any security key, SMS and email codes, saved recovery codes, and any bypass code you issued earlier. Pyron shows a brief confirmation once the devices are gone.
Let the person know their devices have been cleared. The next time they sign in, they set up multi-factor from scratch where your organisation requires it; walk them through setting it up on their profile if they need a hand.