Skip to content

Exempting, deactivating, and resetting

Three person-level switches cover the day-2 realities.

Some identities shouldn’t be prompted — classic examples are service-style logins. Toggling Exempt from MFA lets the person sign in without a second factor while everything is still logged. The audit log marks these honestly as Allow (exempt) — an exempt sign-in means the identity was not factor-verified, and the panel never pretends otherwise.

Put the person back on MFA with the same toggle.

When someone leaves, Deactivate them (with confirmation):

  • Every access they hold — on every resource — stops working instantly.
  • Their audit history is fully preserved.
  • Nothing is deleted, so Activate restores them exactly as they were if needed.

This is the right first move for departures: one action, workspace-wide, reversible.

Lost or changed phone? Reset MFA on the person’s page:

  • The old authenticator stops working immediately.
  • The person receives a fresh enrollment link (or an inline QR if you’re resetting your own).
  • Because each person has a single authenticator, one reset re-binds everything at once — panel sign-in and every machine they use.

Resetting requires a dedicated permission, so helpdesk roles can do it without having broader powers. See roles & permissions.

Situation Use
Person left the company Deactivate
One machine/account should stop Remove or deny that single access
Phone lost or replaced Reset MFA
Login shouldn’t be prompted at all Exempt from MFA (logged, marked exempt)