Reset MFA factors for user in Okta
Automatically reset a user’s Okta MFA factors from a Slack request with Stepwork. Find the user, reset every enrolled factor, and prompt re-enrollment at next sign-in.
- Use case
- Helpdesk & requestsIT
- Best for
- Helpdesk Technician, IT Administrator
- Applications used
Okta
Slack
- Business outcome
- Time savings
The problem
A lost phone locks someone out of everything.
When someone loses or replaces their phone, their MFA factor goes with it. They can’t sign in to Okta, so they can’t reach any app behind it, and they wait in the helpdesk queue until an admin resets their factors.
Each reset means an admin opening the Okta admin console with full rights, often with credentials kept in a shared note. Nobody records who asked for the reset or who did it, and that is the first thing an auditor asks about.
The outcome
They can enroll again at the next sign-in
Stepwork resets every MFA factor on the account. At the next sign-in, Okta asks the person to set up MFA again, and the run records who asked and when the factors were cleared.
- Every enrolled factor is reset.
- The run stops if the email matches nobody, or more than one person.
- The Slack reply names when the reset happened.
The process
From lost phone to a fresh MFA enrollment
Someone loses their phone and asks for help in Slack. Stepwork resets their factors in the Okta admin console, so they can enroll again at next sign-in.
- Step 1
Request it in Slack
The person, or a teammate on their behalf, posts the work email in the helpdesk channel. Stepwork records who asked and when.

- Step 2
Find the user by email
Stepwork signs in to the Okta admin console and searches for the exact work email. If there is no match, or more than one, the run stops instead of guessing.

- Step 3
Reset every factor
Stepwork resets all enrolled MFA factors on the account, the same action an Okta admin takes from the user’s profile.

- Step 4
Confirm and reply in Slack
Stepwork checks that no factors are left enrolled, then replies in Slack. At next sign-in, Okta asks the person to set up MFA again.

Why Stepwork
A lost phone follows one path
A deterministic agent resets every enrolled factor. It does not choose a different set of steps when the Slack message is worded differently, and it stops if the email matches nobody or more than one person.
Similar use cases
Similar use cases
Unlock locked-out user account in OktaLocates a locked user account in Okta admin and unlocks it, restoring sign-in without a password reset.
Force a password change in Microsoft Entra IDResets a user's password in Entra and requires a change at next sign-in.
Create user and assign groups in OktaCreates a new Okta user with name, email, and title, then assigns the group memberships that grant their app entitlements.
FAQ





