Skip to content
synthreo.ai

Reset a User's Password or MFA

How MSP admins send a password reset, reset MFA, or disable login for their own users or a customer's users from the Security card in Synthreo Canopy.

Application: Synthreo Canopy (canopy.synthreo.ai)
Role: MSP Administrator


When a user is locked out, cannot sign in, or needs to re-enroll their second factor, you handle it from User Management in Canopy. Open the user from the list to reach their detail page; the actions live in the Security card there.

The actions are the same whether the account is one of your MSP users or one of a customer’s users - the only difference is where you do it:

  • MSP users - in your own Canopy session.
  • Customer users - inside a delegated session for that customer, so the change applies only to their tenant.

The steps and screenshots live in the canonical Canopy guides:

  • Send a password reset - see Sending a Password Reset. The Send Password Reset button emails the user a link to set a new password.
  • Reset MFA - see Resetting MFA for a User. The Reset MFA button emails the user an enrollment link and then clears their current second factor.

For customer users, open a delegated session first, then follow those same steps within it.


This is the step help desk staff most often get wrong, so be precise with the user:

  1. Canopy emails the user a link to set up a new second factor.
  2. Canopy then clears the user’s current method, setting it to No MFA.

Both halves matter:

  • It does remove their second factor. Until the user follows the emailed link and enrolls again, they can sign in with their password alone. The confirmation dialog says so: “Their current authenticator will be removed and a setup email will be sent so they can enroll a new one.”
  • The email goes first, on purpose. If sending the setup email fails, the method is not cleared, so the user keeps their working authenticator and the reset simply did not happen. That is the safe outcome, not a bug.
  • Nothing forces the user to re-enroll at next sign-in. Re-enrollment happens through the emailed link. If the user says they were never prompted, check that they received the email.

The Security card also shows the user’s current method - None, Email or Authenticator. When it already reads None the Reset MFA button is not offered at all; the card shows “No reset needed” instead.


If the user is not locked out of a credential but needs to be locked out of the product, use the Login control in the same Security card instead:

  • Disable Login locks the account without deleting it or its data. It takes effect immediately: existing sessions are closed and refresh and remember-me cookies are revoked.
  • Enable Login restores access.
  • The Login control is not shown on your own account.

  • Resetting MFA and sending a password reset are separate actions. Neither one performs the other.
  • All User Management actions taken in a delegated session apply only to that customer’s tenant.
  • Changing a user’s email address from this page only initiates the change. The address updates after the user opens the confirmation link sent to the new inbox; until then the current address is unchanged.
  • Signing in to canopy.synthreo.ai requires an active Canopy permission.
Home