In many cases, when someone has issues with Multi-Factor Authentication (MFA), it is because they do not know where to find their one-time password (OTP). They will find their MFA OTP either in the Authenticator App they used to set up MFA or via text to the number they used to set up MFA. Please see Getting Started with MFA for more information.
Note: Administrators are responsible for helping employees resolve MFA and login issues, as WorkBright does not provide direct support for these issues. For security reasons, WorkBright Support cannot reset MFA for employees. Only administrators with Full Access permissions can perform MFA resets, ensuring sensitive account access remains under organizational control.
If they have checked these places and they are still stuck. We have two options. They can use the backup codes that they should have saved during their initial setup (more info found here), or we can reset or delete the current MFA configuration for that staff member. It is recommended to store backup codes in a secure location, such as a password manager, to ensure they are accessible when needed.
Steps to Resolve Common MFA and Login Issues
Verify the Employee’s Account Email: Check the email address associated with the employee’s account to ensure it is correct. Update it if necessary.
Unlock the Account: If the account is locked due to multiple failed login attempts, use the admin tools to unlock it.
Reset MFA Configuration: Clear or reset the employee’s MFA configuration so they can set it up again on their device.
Guide the Employee: After resetting MFA, instruct the employee to log in and complete the MFA setup process on their device. Additionally, administrators can unlock accounts locked due to multiple failed login attempts and verify or update employee account email addresses to resolve login issues.
Note: Deleting will only remove the current configuration; it will not prevent your staff from using MFA. The staff member will be prompted to reconfigure their MFA the next time they log into their account.
To reset a user's MFA, go to “Settings” in your navigation bar.
Note: Administrators can access MFA management tools only if MFA is enabled at the organizational level for at least one user group. For example, MFA must be enabled for at least one user group, such as all admins, all staff, or both.
Go to the sidebar on the right-hand side of the screen and scroll down to “SECURITY” and click on “Multi-Factor Authentication (Users)”.
This will open a page showing all your staff who currently have MFA configured.
Ten emails will be displayed per page. A new page will be created for every set of 10 users.
You will be able to navigate these pages via the page navigator at the bottom of the page.
You can search for a staff member by manually browsing the list or using the email search box at the top.
Once you have found the user you are looking for, click their highlighted email address.
On this screen, we will see their Full Name, Email, what is used to receive their one-time password (OTP) (Auth App or Text), Last Authentication, and Initial Configuration.
If your staff member is using text instead of an Authenticator App, the top bullet will look like this, with the authentication number displayed.
Note: If the staff member needs to update their phone number for MFA, they will need to reset their MFA configuration and reconfigure it with the new number during setup.
To reset this user's configuration, just click the “Delete” button.
After you click the “Delete” button, a pop-up will appear to confirm the action. Click “Cancel” to stop the reset or click “OK” to proceed to reset the MFA.
Note: Deleting will only remove the current configuration; it will not prevent your staff from using MFA. The staff member will be prompted to reconfigure their MFA the next time they log into their account.
After you click “OK”, you will be taken back to the Multi-Factor Authentication (Users) main page. If you have multiple pages, you will return to page 1.
At the top of the screen, you will see a message indicating that you have successfully reset or removed the current MFA configuration for that user.
From this point forward, your staff member will be able to reconfigure their MFA when they log back in. During this reconfiguration process, they will also have the opportunity to generate new backup codes, which should be securely saved for future use.
Additionally, if the reset was to update the phone number, the staff member can enter the new number during reconfiguration.
You can follow our Getting Started with MFA help center article to reconfigure MFA.
Great work; you have now learned how to reset MFA for our staff. If a staff member needs to change the phone number used for MFA, the process involves resetting their MFA configuration and reconfiguring it with the new number during setup. This ensures their account remains secure while updating their contact information.
Best Practices for Managing MFA and Backup Codes
Always store backup codes in a secure location, such as a password manager.
Regularly review and update MFA settings to ensure account security.
Follow organizational guidelines for MFA setup and management.

