Amazon Cognito adds admin API operation to reset user TOTP configurations
News
Amazon Cognito now provides a new admin API operation to reset a user's time-based one-time password (TOTP) multi-factor authentication (MFA) configuration.
- Administrators can remove TOTP device associations when users lose access to their devices
- Users can enroll a new device on their next sign-in without account recreation
- Maintains MFA enforcement while providing a recovery path for locked-out users
- Available in all AWS Regions where Amazon Cognito is available
- Access via AdminDeleteSoftwareToken API using AWS CLI, SDKs, or APIs
This capability eliminates the need to recreate accounts for users who lose access to their TOTP devices, improving user recovery workflows.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Aug 31
2026
2026
Amazon Cognito now supports machine-to-machine authorization without a user pool domain
Aug 7
2026
2026
Amazon Cognito now available as a skill in the Agent Toolkit for AWS
Sep 3
2026
2026
AWS Gateway Load Balancer now supports TCP Reset for faster failure recovery
Jul 15
2026
2026
Amazon Cognito now supports importing users with password hashes
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.