Amazon Cognito now provides a new admin API operation to reset a user’s time-based one-time Password (TOTP) multi-factor authentication (MFA) configuration. When users lose access to their TOTP device, administrators can remove the device association, allowing the user to enroll a new device on their next sign-in.
This removes the need to recreate accounts to recover locked-out users if they lose access to their TOTP device. Customers can maintain MFA enforcement while providing a recovery path.
This new capability is available in all AWS Regions where Amazon Cognito is available. To get started, access the AdminDeleteSoftwareToken API using the AWS CLI, SDKs, or APIs. See the developer guide for instructions.
Categories: marketing:marchitecture/security-identity-and-compliance,general:products/amazon-cognito
Source: Amazon Web Services


