Exempting, deactivating, and resetting
Three person-level switches cover the day-2 realities.
MFA exemption (bypass)
Section titled “MFA exemption (bypass)”Some identities shouldn’t be prompted — classic examples are service-style logins. Toggling Exempt from MFA lets the person sign in without a second factor while everything is still logged. The audit log marks these honestly as Allow (exempt) — an exempt sign-in means the identity was not factor-verified, and the panel never pretends otherwise.
Put the person back on MFA with the same toggle.
Deactivating a person
Section titled “Deactivating a person”When someone leaves, Deactivate them (with confirmation):
- Every access they hold — on every resource — stops working instantly.
- Their audit history is fully preserved.
- Nothing is deleted, so Activate restores them exactly as they were if needed.
This is the right first move for departures: one action, workspace-wide, reversible.
Resetting an authenticator
Section titled “Resetting an authenticator”Lost or changed phone? Reset MFA on the person’s page:
- The old authenticator stops working immediately.
- The person receives a fresh enrollment link (or an inline QR if you’re resetting your own).
- Because each person has a single authenticator, one reset re-binds everything at once — panel sign-in and every machine they use.
Resetting requires a dedicated permission, so helpdesk roles can do it without having broader powers. See roles & permissions.
Which control when?
Section titled “Which control when?”| Situation | Use |
|---|---|
| Person left the company | Deactivate |
| One machine/account should stop | Remove or deny that single access |
| Phone lost or replaced | Reset MFA |
| Login shouldn’t be prompted at all | Exempt from MFA (logged, marked exempt) |