Cognito reset MFA for a user

Viewed 402

I created a user pool in AWS Cognito with MFA set to optional MFA

and adaptative authentication as Optional MFA.

Adaptative authentication

The MFA method enabled for users is TOTP, which I enable by calling SetUserMFAPreference.

My use case requires that any user that uninstalls their TOTP app or buys a new mobile phone can install it again in their new device by generating a new valid TOTP token. The only way to generate a new TOTP valid token is by calling AssociateSoftwareToken, but it requires an access token that the user does not have as they are not signed in yet.

I tried with SetUserMFAPreference setting enabled=false but it did not work. Sign in still requires the TOTP challenge.

Is there any way to disable MFA or regenerate a new TOTP token to achieve below behaviour?

1 Answers

So I found a workaround for this problem.

This disable MFA function is not allowed in Cognito. What we did is, instead of trying to create a new token, we decided to store the existing one and reuse it every time the user wants to reinstall the authenticator app in another device.

This way, we do not need to create a new token, just reuse the existing one.

Related