Amazon Cognito Adds Admin API to Reset User TOTP MFA Configurations
Amazon Cognito now includes a new admin API operation for resetting a user's Time-based One-Time Password (TOTP) multi-factor authentication (MFA) configuration. This allows administrators to remove the device association for users who lose access to their TOTP device, enabling them to enroll a new one during their next sign-in. The capability eliminates the need to recreate user accounts for recovery, ensuring MFA enforcement is maintained. This functionality is available in all AWS Regions supporting Amazon Cognito, accessible through the AWS CLI, SDKs, or APIs via the `AdminDeleteSoftwareToken` API.
Features (1) ›
- Reset User TOTP MFA Configurations
Amazon Cognito provides a new `AdminDeleteSoftwareToken` API operation to reset a user's TOTP multi-factor authentication (MFA) configuration. This allows administrators to disassociate a lost TOTP device, enabling users to enroll a new device on their next sign-in without requiring account recreation. The capability maintains MFA enforcement while providing a critical user recovery path, and is available in all AWS Regions where Amazon Cognito is present.
https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-cognito-totp-reset/
Related releases
- Mountpoint for Amazon S3 adds memory usage controls AWS What's New ·
- AWS Backup Expands Cross-Region Copy and Air-Gapped Vaults for DocumentDB AWS What's New ·
- Amazon Connect Customer adds support for unplanned shrinkage in agent schedules AWS What's New ·
- AWS Glue now supports catalog federation for remote Apache Iceberg in GovCloud (US) regions AWS What's New ·
- Amazon Connect Customer Adds Points-Based Scoring for Agent Evaluations AWS What's New ·
- HashiCorp Terraform AWS Provider v6.62.0 Adds New Resources and Enhancements Terraform AWS Provider Releases ·