Amazon Cognito adds admin API operation to reset user TOTP configurations

Amazon Cognito TOTP MFA Reset
Amazon Cognito now provides a new admin API operation to reset a user's time-based one-time Password (TOTP) multi-factor authentication (MFA) configuration. When users lose access to their TOTP device, administrators can remove the device association, allowing the user to enroll a new device on their next sign-in. This removes the need to recreate accounts to recover locked-out users if they lose access to their TOTP device. Customers can maintain MFA enforcement while providing a recovery path.
What to do
- Access the AdminDeleteSoftwareToken API using the AWS CLI, SDKs, or APIs.
- Refer to the developer guide for instructions.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



