Multi-Factor Authentication - Microsoft Account Reset

Prev Next

The IT Support Agent leverages multi-layered intelligence—including keyword analysis, validation of user identity, dynamic prompting, and knowledge base integration—to support multi-factor authentication (MFA) resets. The agent ensures compliance with company policy and security best practices, and securely guides users through identity verification and reset workflows.

Support Agent for MFA reset performs the following:

Fetching User Details

Before proceeding with any password or MFA reset, the agent ensures the user's identity is verified and that the correct account is being addressed:

  • Fetches and validates user details (official email, employee ID, associated phone numbers) against their profile

  • May prompt the user for additional information if discrepancies arise

  • Ensures compliance with security best practices for identity verification

If user details are matched successfully then, proceeds to reset workflow. If mismatch or potential security concern then, notifies user and escalates as per company security policy

Notes

  • All reset transactions are logged for audit and compliance purposes

  • Agent always references the latest knowledge articles and company policies

  • Phone numbers remain on file and are never deleted during MFA reset

  • If user identity cannot be verified, the agent escalates the request to human support

  • System administrators may configure policy messaging and verification logic via Summit Knowledge integration

Multi-Factor Authentication (MFA) Reset - Microsoft Account

The MFA reset process is designed to provide a secure, user-friendly experience while strictly maintaining the integrity of user data and following all relevant company policies. The agent ensures users are guided appropriately based on their current MFA configuration and are always informed of what actions are taken and any next steps required.

  1. The agent confirms user identity by fetching profile information:

    • Official email address

    • Employee ID

    • Associated phone numbers (primary and secondary)

  2. The agent offers to reset MFA, informing the user of the process and policy. You can validate two scenarios as follows:

    Note

    The agent ensures that no phone number is erased during the reset, only updating MFA configuration as necessary.

Configure MFA and Reset

To reset MFA you must have first configured for your user ID. then request bot to reset MFA. Upon resetting MFA, the details about the MFA in the account is erased. You will have to configure to reset again.

To validate this scenario, perform the following steps:

  1. Log in to the account to set up MFA for your current account.
    You will be enabled to login using default sign-in method such as Phone number or Password.

    Figure: Authenticate

  2. Add the sign-in method and select Microsoft Authenticator.

    Figure: Microsoft Authenticator Method

  3. Set-up the account on your Authenticator App. You will be able to see the Authenticator added pop-up after successfully linking to the app.

    Figure: Authenticator Added

  4. After you click Done you can see the MFA Method added to your account.

    Figure: Microsoft Authenticator

  5. Log in to the Application with the above account.

  6. Prompt the bot to reset MFA, the Agent resets the MFA and you will need to set-up again.

    Figure: MFA Reset

  7. Go back to the your account and validate if the MFA Method has been removed.

    Figure: MFA Method Removed

  8. On the application, again prompt the Agent to reset MFA, it displays that no authenticator methods found and account is ready for fresh MFA setup.

    Figure: No Authenticator Methods Found

MFA not set-up

Upon fetching the user details, if the MFA is not set up it simply displays to set-up MFA for the user account. Support Agent has the capability to check if MFA is set-up for the current User ID.

To verify, perform the following steps:

  1. Log in to the Application as an End User.

  2. Enter prompt as “please reset the MFA”.

  3. Support Agent fetches the details and responds MFA has not set-up for the User. Only after configuring MFA you can reset MFA.

    Figure: MFA not set-up