Version Affected: All
Overview
When a user has forgotten their PIN for the Passcode app, there is no way to reset it directly.
Cause
For security, all Passcode data is wiped after 10 failed PIN attempts by default. This limit can be changed on the Post Auth page of the enrollment realm. Rather than allowing a direct PIN reset, the design requires the user to re-register, since going through the registration workflow again — including any multi-factor authentication (MFA) configured on the registration realm — lets the user set a new PIN securely.
To set a new PIN:
- Enter an incorrect PIN 10 times. Warning: this wipes out all Passcode data.
- This brings up the screen shown below.
- Click Add Account.
- Enter the registration URL when prompted.
- Once registration is complete, the user can set a new PIN.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.