Glossary
Factor reset
An administrator action that removes a user's MFA enrollments so they can enroll again; routine for support, and the key step in helpdesk social engineering.
A factor reset removes one or all of a user's enrolled authenticators so the user can enroll new ones, typically after a lost or replaced phone. In the Okta System Log it appears as user.mfa.factor.reset_all or user.mfa.factor.deactivate, often next to user.account.reset_password. When the actor is a helpdesk agent and the target another user, the event is normal support work, unless the caller was an impersonator. The telling follow-up is a user.mfa.factor.activate for that user from a network they have never used. See helpdesk social engineering and MFA resets.