Manage User Security & MFA Settings
View and manage MFA status, phone numbers, and authenticator apps from the User Details page.
Overview
Admins can view and manage a user's Multi-Factor Authentication (MFA) settings directly from the User Details page in the Manage Organization panel. The Security & MFA section provides visibility into whether a user has a verified phone number and/or a configured authenticator app, along with quick-action buttons to update these settings.
This feature is available to users with "Owner" or "Admin" roles who have access to the Manage Organization panel.
Accessing the Security & MFA Section
- From Manage Organization > Users. You can navigate there directly at avochato.com/manage-users.
- From Manage Organization > Security. You can view all users who do not have MFA configured directly at https://www.avochato.com/manage-security
- Click on a user's name to open their User Details page.
- Scroll down to the Security & MFA section.
Understanding MFA Status Indicators
The Security & MFA section displays the current configuration status for each MFA method:
When MFA is fully configured:
Phone β Shows the verified number with a green Verified badge
Authenticator App β Displays a green Configured badge

When MFA is not configured:
Phone β Displays a red Not set badge
Authenticator App β Displays a red Not configured badge

Available Admin Actions
The action buttons displayed depend on the user's current MFA status.
When MFA is not configured (phone and/or authenticator app missing):
- Add Phone Number β Navigates to the Edit User page where you can add a phone number for the user.
- Send Authenticator Setup Link β Sends an email to the user with instructions to configure their authenticator app (e.g., Google Authenticator, Authy, or Microsoft Authenticator).
When MFA is fully configured (both phone and authenticator app set):
- Update Phone Number β Navigates to the Edit User page to change the user's phone number on file.
- Reset Authenticator App β Resets the user's authenticator app configuration and sends them an email to set it up again.
These buttons are not displayed for Avobot (automated/bot) users since MFA does not apply to them.
Password Resets & Log Out of All Sessions
The Profile Information section includes a button to reset password and/or log user out of all sessions. The reset password button will trigger the user to receive a password reset email.
When Should I Use This?
- Onboarding a new user onto MFA: If neither phone nor authenticator app is configured, use the action buttons to kick off setup.
- A user lost access to their authenticator app: Use Reset Authenticator App to clear their existing configuration and send a new setup link.
- A user changed their phone number: Use Update Phone Number to update their MFA phone number on file.
- Auditing MFA compliance: Quickly check whether each user has both verification methods in place.