What problem does it solve?
This Skill helps recover access when Microsoft Entra ID MFA is failing or the user has lost or changed their authenticator method, by guiding a controlled MFA reset and re-enrollment process.
Core Features & Use Cases
- Identity-verified MFA reset flow: Enforces mandatory identity verification before any MFA changes, with additional approval requirements for admin accounts.
- MFA method guidance and removal planning: Determines the MFA reason (new phone, lost device, number change, unknown), reviews current methods, and provides removal/re-enrollment instructions.
- Connector-aware execution: If identity connectors are available, supports method-removal actions; otherwise provides a safe manual portal flow and documents the outcome.
Use case example: A user reports they lost their phone and can’t receive MFA codes; the helpdesk agent verifies identity, removes stale MFA methods, and directs the user through Microsoft Authenticator re-registration to restore access.
Quick Start
Ask to reset MFA for a specific user by providing their username or UPN and the reason, for example: run the mfa-reset skill with [email protected] new-phone.