Amazon Cognito adds admin API operation to reset user TOTP configurations

Published
August 26, 2026
https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-cognito-totp-reset/

Amazon Cognito TOTP MFA Reset

Amazon Cognito now provides a new admin API operation to reset a user's time-based one-time Password (TOTP) multi-factor authentication (MFA) configuration. When users lose access to their TOTP device, administrators can remove the device association, allowing the user to enroll a new device on their next sign-in. This removes the need to recreate accounts to recover locked-out users if they lose access to their TOTP device. Customers can maintain MFA enforcement while providing a recovery path.

What to do

  • Access the AdminDeleteSoftwareToken API using the AWS CLI, SDKs, or APIs.
  • Refer to the developer guide for instructions.

Source: AWS release notes




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.