We have a user who is experiencing issues with Atlassian two-step verification. The user is repeatedly required to obtain and use a Recovery Key, which is causing ongoing access difficulties.
We investigated the issue and attempted to identify an administrator who could manage or reset the user's two-step verification settings. However, we could not find any existing Atlassian administrator account with sufficient permissions to manage the affected user's authentication settings.
Could you please assist with:
Hi - Welcome to the Atlassian Community!
A few important points here.
First, an organization admin cannot directly reset another user’s personal two-step verification unless that account is managed under the organization’s authentication policies. If the account is unmanaged, the user generally has to recover access themselves through Atlassian’s account recovery flow.
I would check the following:
In admin.atlassian.com → Directory → Managed accounts, search for the user.
If the account appears there, confirm which organization manages it and whether an authentication policy is applied.
If the user does not appear as a managed account, then their Atlassian account is likely controlled outside your organization, and you won’t be able to reset their personal 2SV settings from your admin console.
Regarding the repeated Recovery Key prompt, that usually points to an issue with the user’s current 2SV setup or recovery process rather than Jira permissions.
If there is currently no organization admin with access to manage the organization, that is a separate issue. In that case, I would contact Atlassian Support and ask them to help recover or re-establish organization administrator access. They will normally need to validate ownership of the organization/domain before making any administrative changes.
So I would separate this into two checks:
1. Who manages the user account?
Check whether the account is a managed account in your organization.
2. Who manages the Atlassian organization?
If there is genuinely no active org admin, this will likely require Atlassian Support intervention.
For the user’s 2SV itself, if the account is unmanaged, the safest path is usually for the user to go through Atlassian account recovery rather than trying to solve it from Jira administration.
Hope this helps!
Hello @faghaarabi admin
We are community members, so we cannot help you with that.
You should contact https://www.atlassian.com/company/contact/purchasing-licensing#/ or Support.atlassian.com
Best,
Arek 🤠
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
One addition to my earlier reply, because there are a few checks you can do before Atlassian has to investigate this privately:
1. Ask the user to check their account at Atlassian Profile Management (https://id.atlassian.com/manage-profile/profile-and-visibility) to see if it’s managed by an organization.
2. If it is, and you have an Organization Admin, they can go to Atlassian Administration > Directory > Managed accounts > [User] > Security, and choose "Reset two-step verification."
3. If two-step verification (2SV) is required, temporarily switch the user to a policy where it's optional, reset it, have them re-enroll, and then switch them back.
4. If the account isn’t managed, the user should follow the recovery link (Can’t find your recovery key? > Send recovery email), which will lead to a 24-hour wait.
If you don’t have an active Organization Admin, Atlassian Support can help transfer the admin role after trying to contact the previous one. After that, make sure to have at least two admins to avoid future issues.
If the user spots a strange organization name, just create a private ticket with Atlassian Support to get help.
Give users admin permissions | Atlassian Support
Best,
Arek 🤠
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
When you have only one user with these problems, perhaps you might want to look at the browser settings of that user. Normally, even with 2FA, the user should remain logged in for a long time, provided he/she connects regularly - as it probably is with all your other users. So perhaps that particular browser is set to high security or to erase cookies after each session. If that is the case, an exception for the JIRA domain should be set in the security rules. Or he/she could try another browser.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.