Reset TFA for a customer
Use an Admin reset when a verified customer has lost both the authenticator and every recovery code. The administrator needs the Reset Customer Two-Factor Authentication ACL permission.

Before resetting
Follow your organization's identity-verification process. A reset removes the second-factor requirement from that account, so an email address or order number alone is not enough evidence of ownership.
Reset the account
- Open Customers > All Customers.
- Edit the customer.
- Check the read-only Two-Factor Authentication Enabled status.
- Choose Reset Two-Factor Authentication and confirm the action.
- Tell the customer to sign in and enroll a new authenticator.
The reset clears the enabled state, encrypted secret and recovery-code set. It does not change the customer's password or terminate unrelated sessions.
If TFA is mandatory, the next normal sign-in sends the customer through setup before completing authentication. If TFA is optional, the customer must enable it again from My Account.
Magento writes an Admin reset event to the standard application log with the internal customer ID, not the secret or recovery codes.