BoldDesk 2FA Reset & Recovery Codes: Complete Admin Guide
This article explains how BoldDesk administrators and agents can help customers regain access when they lose their Two‑Factor Authentication (2FA) method. It covers sending a recovery code, guiding the customer to re-enable 2FA, and validating Customer Portal security settings in the Admin Center.
What You Can Do in BoldDesk
- Send a recovery code to a customer directly from the Contacts record.
- Guide the customer to log in with the code and reset or re‑enable 2FA in their Customer Portal profile.
- Verify prerequisites in Admin → HelpDesk → Settings → Customer Portal → Security so recovery is available.
- Audit actions and diagnose delivery issues under Admin → General → Audit Logs.
Send a Recovery Code (Agent/Admin Workflow)
Perform these steps in the HelpDesk workspace:
-
Open Contacts.
-
Search and open the Contact (customer) record.
-
Select the More (⋮) menu in the top‑right.
-
Click Send Recovery Code.
-
Ask the customer to check their email and use the code to sign in to the Customer Portal.
- The recovery code is single‑use and time‑bound. If the customer’s code expires or is lost, repeat the steps to send a new one.
- 2FA recovery code emails are always sent using the support email address configured for the default brand, regardless of the brand from which the recovery codes are requested. This behavior is expected and may result in users receiving recovery code emails from the default brand’s support email address.
Customer Steps: Log in and Reset 2FA
After receiving the recovery code, the customer:
-
Opens the Customer Portal sign‑in page.
-
Enters their email and Recovery Code.
-
After login, goes to Profile → Security.
-
Selects Enable 2FA or Reset 2FA and completes the setup.
-
Saves changes and stores new backup/recovery codes securely.
2FA Authentication Errors – Common Causes and Resolution
If you encounter an error while completing two-factor authentication (2FA), it is typically due to a mismatch between the entered code and the one generated by your authenticator app. The most common causes include:
Time Synchronization Issues
2FA codes are time-based (TOTP). If your device’s time is not properly synchronised, the generated code may be invalid. Ensure that your device is set to automatic date and time, and refresh it by toggling the setting off and on if needed.
Duplicate or Outdated Authenticator Entries
Multiple entries for the same account in your authenticator app can lead to confusion and incorrect code usage. Remove any duplicate or outdated entries, then re-scan the QR code and use the newly generated authentication code.
Verifying these factors usually resolves most 2FA-related issues and ensures successful login.
Roles & Permissions
To allow agents to execute recovery actions:
-
Navigate to Admin → Users & Permissions → Roles and Permissions.
-
Open the relevant Role.
-
Ensure the role has privileges to view/update Contacts and perform Customer Portal security actions (manage settings under admin).
-
Assign the role to the intended Agents.
Monitor and Troubleshoot with Audit Logs
Use Admin → General → Audit Logs to verify and diagnose the recovery flow:
- Activity Logs – Confirm which agent sent a recovery code and when.
- Access Logs – Validate customer sign‑in attempts using the recovery code.
- Email Failure Logs – Troubleshoot recovery email delivery issues.
Troubleshooting
-
The customer did not receive the recovery code email
Check the following:- Confirm the customer email address is correct in the Contact record.
- Review Admin → General → Audit Logs → Email Failure Logs for delivery failures.
- Re-send a new recovery code if the original code expired or was not received.
- Also confirm customer expectations about sender identity: Recovery code email sender uses the default brand support email address, which may differ from the brand the customer expects.
-
The customer says the recovery code is invalid or expired
- Recovery codes are time-bound. Send a new recovery code from the Contact record.
- Confirm the customer is using the most recently received recovery code email.
-
The agent cannot see “Send Recovery Code” in the Contact record
- Validate agent role permissions in Admin → Users & Permissions → Roles and Permissions.
- Confirm the role includes view/update Contacts and applicable Customer Portal security privileges.
-
The customer can sign in with the recovery code but cannot complete 2FA setup
- Confirm the customer is in Customer Portal → Profile → Security and completes Enable 2FA or Reset 2FA.
- For authenticator-code failures, address time synchronization and duplicate authenticator entries.
Frequently asked questions
-
Can an agent revoke a recovery code after sending it?
Recovery codes are single-use and time-bound. If recovery access must be invalidated, send a new recovery code. The most recently issued recovery code supersedes earlier codes. -
Does the customer need to reset or enable 2FA after using a recovery code?
Yes. The recovery code is only for sign-in. The customer should immediately go to Customer Portal → Profile → Security and select Enable 2FA or Reset 2FA. -
Why did the customer receive the recovery code email from a different brand email address?
Recovery code emails are sent from the support email address configured for the default brand, regardless of which brand initiated the request. -
Where can administrators verify whether a recovery code was sent?
Use Admin → General → Audit Logs → Activity Logs to confirm the sending event, including the sender and timestamp. -
Where can administrators troubleshoot recovery email delivery failures?
Use Admin → General → Audit Logs → Email Failure Logs. -
Can administrators restrict which agents can send recovery codes?
Yes. Configure agent permissions in Admin → Users & Permissions → Roles and Permissions so only authorized roles can view/update Contacts and perform the recovery action. -
Are ticket SLAs or ticket automations affected by sending a recovery code?
Recovery is separate from ticket SLAs. Any logging for related actions can be verified in Admin → General → Audit Logs. -
What should a customer do if 2FA still fails after the customer already used a recovery code?
If the customer already used the recovery code and 2FA still fails, the customer must either wait the 24-hour lockout period to try again or contact BoldDesk Support to reset two-factor authentication.