If multi-factor authentication (MFA) is enabled, and a user loses or breaks a device with the MFA secret associated with it, there are three ways to reset the secret associated with the MFA device:
- If the user has an additional MFA device set up, they can log in with the secondary device and remove the MFA secret associated with the lost MFA device.
- If the user does not have a secondary device, or if they cannot log in and remove the MFA secret, the account administrator can reset MFA for the user for use on a new device, however, this removes all MFA devices the user has set up.
- If the user has saved one-time use passwords, these can be used to log into the account. Each code can be used only once, and they must be using in the order printed.
A. Reset MFA from a Secondary Device (User)
Use the following steps to log in with a secondary device and remove the MFA secret associated with the lost MFA device:
- Log into login.barracuda.com, and go to My Profile.
- In the Multi-Factor Authentication section, click Delete in the Options field for the lost device.
- In the Delete MFA Device dialog, enter the authentication code from any other MFA device, and then click Delete.
B. Reset MFA for a User from Account Administrator Role
Use the following steps to reset the MFA secret:
- Log into login.barracuda.com as the Account Administrator.
- Navigate to the Home > Admin> Users page.
- Click on the name of the user.
- In the User Details section, click Reset MFA Settings:
- A confirmation dialog displays:
- Click OK to confirm your selection.
An email notification is automatically sent to the user notifying them that the MFA devices have been reset.
C. Log in Using One-Time Use Passwords
Use the following steps to log in with a secondary device and remove the MFA secret associated with the lost MFA device:
- Log into login.barracuda.com, and enter one of the codes from your list of one-time use passwords that you printed from the Multi-Factor Authentication section of the My Profile page after setting up MFA.
- Go to the Home > My Profile page.
- Click Add New Device; the Add New Multi-Factor Authentication Device page displays.
- Either scan the QR code, or enter the secret code into the authentication tool on your mobile device, and then click Save.
- In the Multi-Factor Authentication section, click Delete in the Options field for the lost device; the Delete MFA Device dialog displays.
- Enter the MFA code from the just added device, and then click Delete to confirm your selection.