Skip to main content

How can an Account Owner or Administrator unblock a user who has lost access to their authentication methods?

Step-by-step guide to restoring a user's access.

A guide for Account Owners and Administrators to restore a user's access via a recovery code

Context: What this article is about

Spendesk uses Strong Customer Authentication (SCA) to keep accounts secure. SCA is an extra verification step required when signing in or approving certain actions. It works through one of the following methods:

  • 📱 An authenticator app (such as Google Authenticator), which generates a temporary code

  • 💬 SMS, where a one-time code is sent to your registered phone number

  • 🟣 The Spendesk mobile app, which sends a push notification to approve the action

This article covers a specific situation: a user can still log in to Spendesk but is blocked at this extra verification step because they no longer have access to their authentication method (e.g. they lost their phone, changed phone number, changed devices, or deleted the app).

ℹ️ This is not about a user who has forgotten their password or been fully locked out of their account. It only applies to users who cannot complete the SCA verification step.

👤 User perspective: What the blocked user experiences

When a user has lost access to their authentication method, they will:

  • Be able to reach the Spendesk login page and enter their credentials normally

  • Get stuck at the verification step, where they are asked for a code or approval they can no longer generate or receive

  • Need to contact their Account Owner or Administrator to request a recovery code

The user should reach out through a trusted channel (e.g. direct message, phone call). They should not rely solely on email, as their email account may also be at risk.

🔐 Admin / Account Owner perspective: How to restore the user's access

Once a user has reached out for help, an Account Owner or Administrator can generate a recovery code on their behalf.

⚠️ Always verify the requester's identity before taking any action. If phishing is suspected, treat the account as compromised and do not proceed.

Steps:

  1. Go to Settings > Organisation.

  2. Open the blocked user's profile and click Edit member's profile.

  3. Navigate to the Security tab.

  4. Click Generate a recovery code.

  5. A confirmation prompt will appear. Click I confirm only if you are certain of the requester's identity.

  6. Choose how to share the recovery code:

    • Manual sharing - The code is displayed on screen. Use this if you have any doubts, and share it via a different channel from the one used to contact you (e.g. a phone call rather than email).

    • Email delivery - The code is sent automatically to the user's registered email address. Use this only if you are fully confident in their identity and their email account is not at risk.

  7. Authenticate yourself when prompted.

  8. The recovery code is delivered - either sent by email automatically, or displayed for you to share manually.

✅ What happens next (user side)

Once the user receives the recovery code, they can use it to bypass the verification step and sign back in to Spendesk:

  1. Sign in to Spendesk.

  2. Click on "Use an alternate authentication method".

  3. Click on "Enter a recovery code".

  4. You are logged in to Spendesk! 🎉

💡 Tip: Once back in, make sure to set up a new authentication method - either a new authenticator app, SMS, or the Spendesk mobile app - to avoid losing access again.

Did this answer your question?