How to Reset Someone's Authenticator App
When somebody has lost the phone with their authenticator app on it, or has a new phone, the system administrator resets their authenticator on the Sign-in screen, and they then set one up again on their new phone. Open the menu and, under Administration, select Sign-in, then use Reset beside the person's name in the People list.
How do I reset the authenticator of somebody who lost their phone?
Open the menu, select Sign-in under Administration, find the person in the People list, select Reset beside their name, and then Reset it to confirm. When the setting is Required, the next time they sign in over the web, after their password, ABM Service takes them to setting up an authenticator app again, on their new phone; when it is Optional, they sign in with their password and set up a new one from Authenticator in their menu if they want to.
- Open the menu with Menu (or Navigation menu on the Calls, Customers and Scheduler screens).
- Select Sign-in under Administration.
- Find the person in the People list on the Sign-in screen. The list is in order of name.
- Select Reset beside their name. The row asks: Their next sign-in will ask them to set it up again.
- Select Reset it to go ahead, or Keep it to leave it as it is.
When it is done, their row reads Not set up. If the reset could not be made, the reason appears at the top of the Sign-in screen and their row still shows Set up on. The reset cannot be undone: the old phone's codes stop working for good, so even if the lost phone turns up, they set up again.
The reset does not sign them out anywhere they are already signed in. It takes effect at their next sign-in over the web, where the Authenticator app setting decides what happens: under Required they must set one up before they can go on, and under Optional or Off they are not asked, even though the Reset question says their next sign-in will ask them.
There is no button to sign one person out either. If somebody must lose access today, for example because they have left, have them removed from ABM's own user list so they cannot sign in again, and ask whoever looks after your ABM Service server to restart it, which ends every web sign-in. A reset clears their authenticator for this company only: if they also sign in to another ABM company over the web, reset that one separately, on that company's own Sign-in screen.
What does the People list on the Sign-in screen show?
The People list on the Sign-in screen shows every ABM user, in order of name, and whether each has set up an authenticator app. The line above it counts them, for example 12 people, 3 with an authenticator., or ends none with an authenticator yet. when nobody has.
Under each name, the list says:
- Not set up — the person has no authenticator. There is nothing to reset, so there is no Reset button.
- Set up on and a date — the day they set up their authenticator app. Reset is beside it, except on your own row.
- ABM no longer lists this user, after the set-up date — ABM Service still holds an authenticator for a user number ABM has removed. The row is named User and the number, and Reset clears it.
The names come from ABM's own list of users, the same one people choose from when they sign in, so the list shows everybody on it, whichever companies they have been given. While it is being read the list says Reading who is on ABM's list….
The People list on the Sign-in screen only reads ABM's list. You cannot add a person, change a name or a password, or remove somebody here: whoever looks after ABM at your company does that in ABM's own user list. The list is on screen only: the Sign-in screen has no button to export or print it.
The list is useful beyond resets. With Optional chosen, it shows who has taken up the authenticator app; before switching to Required, it shows who will be asked to set one up at their next sign-in.
Why can't I reset my own authenticator?
The Sign-in screen never offers Reset on your own row, and says so under the list: Your own is not reset from here. If you lose your phone, whoever looks after this server can clear it for you.
This is deliberate. As user 1, you can clear anybody's authenticator. If you could also clear your own from a browser, somebody who found your computer signed in could clear it, set up their own phone, and take over the system administrator's sign-in without ever needing a code. Keeping your own reset on the server itself closes that gap.
If you lose your phone, contact whoever looks after your ABM Service server, or your software supplier's support team. Once they have cleared it, your next sign-in over the web asks you to set one up again if the setting is Required; if it is Optional, you sign in with your password and set up your new phone from Authenticator in your menu. The ABM Service desktop app does not use authenticator codes, so if you have it on your computer you can still reach ABM Service there in the meantime.
What does "ABM no longer lists this user" mean?
ABM no longer lists this user under a name in the People list on the Sign-in screen means ABM Service still holds an authenticator for a user number that is no longer in ABM's list of users, usually because the user was removed in ABM. Their row shows User followed by their number, because ABM no longer has a name for it.
They stay on the list so that you can still clear their authenticator. Select Reset and then Reset it on their row if they have left the company; the row then disappears from the list.
What if the People list says the names could not be read?
If the People list says The names could not be read from ABM's control database, so the list below is not here. followed by a reason, ABM Service could not reach ABM's list of users. The Authenticator app setting above it still works, because it is kept in your company's own database. Try the Sign-in screen again later; if it keeps happening, give the reason to your software supplier's support team or IT contact, because ABM's control database may be unavailable or not yet set up for this site.
Why is everybody being asked to set up their authenticator again?
If everybody who had an authenticator is suddenly asked to set it up again, with the words Your authenticator needs setting up again on this server, the ABM Service server has usually been moved to another machine, or the database restored somewhere else. The secret each phone shares with the server cannot be read on the new machine, so each person scans a new square once and carries on as before.
Nobody is locked out and nothing is lost, and you do not need to reset anybody: each person is taken through it at their own next sign-in, even when the setting is Optional.
Codes being refused with That code was not accepted is a different fault, most often the server's clock, and is not fixed by setting anything up again.
Why is everybody's code refused with "That code was not accepted"?
When everybody's authenticator code is refused at once with That code was not accepted. Check your authenticator app and type the code it is showing now., the likely cause is the clock on the server ABM Service runs on. Ask whoever looks after your ABM Service server to correct its time; codes are accepted again straight away, and nobody has to set anything up again.
Each code is worked out from the time and lasts thirty seconds, and ABM Service accepts only the current code and the one just before or just after it. A server whose clock is more than about a minute out therefore refuses every code, with the same message a mistyped code gets.
Resetting people's authenticators with Reset on the Sign-in screen does not help: the new authenticator is checked against the same wrong clock, so setting it up fails too. While the clock is being put right, people can still reach ABM Service with the ABM Service desktop app, which never asks for a code. If people must sign in over the web before then, choosing Off under Authenticator app on the Sign-in screen, which you can also reach from the desktop app's menu, stops the codes being asked for and keeps what everybody has set up; choose Optional or Required again once the clock is right.
When only one person's code is refused, the cause is usually on their side:
- Their phone's clock is wrong — set the phone to take its date and time automatically.
- The code changed while they typed it — wait for the next code and type it straight away.
- The code was used a moment ago — a code is accepted only once, so signing in on a second browser needs the next code.
If none of those helps and they still have the phone, Reset their authenticator and let them set it up again.
What does "That took too long. Sign in again." mean?
When somebody signing in to ABM Service over the web sees That took too long. Sign in again., more than five minutes passed between their password being accepted and them typing a right authenticator code, or finishing setting up their authenticator app. The page takes them back to choosing their name, and they simply sign in again with their phone to hand. Nothing is wrong with their authenticator, their account or the server's clock, and there is nothing to reset on the Sign-in screen.
The five minutes start when the password is accepted. A wrong code does not use them up: the person types the next code their app shows, on the same sign-in, until the five minutes run out. The limit is long enough to find a phone, unlock it and open the app, and short enough that a sign-in somebody walked away from cannot be finished after lunch.
The same message can come sooner in two cases:
- The ABM Service server was restarted while they were typing, because a restart forgets every half-finished sign-in.
- They were setting up an authenticator and finished setting one up in another browser window meanwhile.
Reloading the page part of the way through also starts the sign-in again from the list of names, without the message. After the message, a square they were about to scan is no longer any use: they sign in again and scan the new one. On their own Your authenticator page, reached from Authenticator in their menu, the same time limit reads That took too long. Start again., and they select Set up again.
Can I unlock somebody who typed a wrong password or code too many times?
There is nothing to unlock. ABM Service never locks anybody out after wrong passwords or wrong authenticator codes, and the Sign-in screen under Administration has no unlock button. Instead, each wrong password or code is answered a little later than the one before: one second for the first, then two, then four, doubling up to half a minute, and ABM Service looks at nothing more from that person until the answer has been given. The waits are forgotten an hour after the last wrong attempt, or as soon as that person finishes signing in, and one person's mistakes do not slow anybody else down.
If somebody tries again while their wait is still running, for example in a second browser window, they see The server is busy signing people in; try again in a moment. Waiting a little and trying once more is enough.
When somebody keeps failing, what to do depends on the cause:
- A forgotten password — office passwords are ABM passwords, so whoever looks after ABM at your company sets a new one in ABM's own user list. ABM Service has no password of its own for office staff.
- A lost or replaced phone — select Reset beside their name in the People list on the Sign-in screen, then Reset it.
- Everybody's codes refused at once — the likely cause is the server's clock, not the people.