This article is part of the X-Cart Two-Factor Authentication (2FA) Guide.
If a secondary administrator loses access to their authenticator app (e.g., lost or replaced their smartphone) and does not have their saved backup codes, they will be locked out of the X-Cart Admin area.
In this scenario, a Root Administrator can reset (remove) the existing 2FA configuration for that user, allowing them to regain access and set up 2FA from scratch.
How to reset a user's 2FA
To revoke the 2FA configuration for a specific administrator:
In your X-Cart Admin area, go to Store > Users.
Locate the administrator who is locked out.
Click on the user's email to open their profile details, navigate to the Two-Factor Authentication tab, and click the Remove 2FA button at the bottom of the page.
A confirmation pop-up will appear. Click the red Remove 2FA button to confirm your action.
What happens after the reset?
Once you confirm the removal:
The user's previous secret key and backup codes are permanently invalidated.
The 2FA status for their account changes to Not configured (indicated by a yellow warning block in their profile).
Forced Reconfiguration: Upon their next login, after entering their password, the user will be presented with the Two-Factor Authentication Required screen. They will be forced to scan a new QR code and save new backup codes to access the admin area.
Note: The forced reconfiguration upon the next login triggers automatically after a 2FA reset to ensure the account remains secure, even if the global Require 2FA for all admins setting is turned off.
Can't find answers you're looking for?
Email us at support@x-cart.com. We will be happy to help!
Related articles
