This article covers how to recover access to the SentinelOne console when multi-factor authentication (MFA) is broken, inaccessible, or cannot be completed.
Common Symptoms
MFA codes are not being accepted on the SentinelOne console login screen
The MFA enrollment QR code is no longer valid or cannot be scanned
The authenticator app was removed, lost, or set up on a new device and the old codes no longer work
MFA enrollment was never completed and the setup window has expired
Reset Options
There are two ways to recover access, depending on your situation:
Option 1: MFA Re-enrollment (Preferred)
If your SentinelOne user account is still active and only the MFA registration needs to be cleared, a Guardz Support engineer can trigger an MFA reset from the backend. After the reset:
You will receive a re-enrollment link or prompt the next time you log in to the SentinelOne console.
Follow the on-screen steps to register a new MFA device (scan the QR code with your authenticator app).
Once enrolled, your new MFA codes will work immediately.
This option preserves your existing user account, settings, and permissions. It is the preferred approach and does not require you to be removed from any tenants.
Option 2: User Account Reset (Fallback)
In some cases — for example, where the SentinelOne user record is in an unrecoverable state — a support engineer may need to delete and recreate the user account. This results in:
A new invitation email sent to your address
A fresh MFA enrollment flow
Your existing role and tenant access restored after the account is recreated
Note: This is a standard account reset, not a data loss event. Your user data and tenant associations are restored after the new account is set up. If you have concerns about specific permissions or settings, let the support engineer know before they proceed.
How to Request a Reset
Contact Guardz Support and provide the following:
The email address associated with your SentinelOne account
The tenant or organization name
A brief description of the issue (e.g. 'authenticator app replaced', 'codes not accepted')
A support engineer will confirm which reset option applies and carry out the reset. The process typically takes a few minutes once the request is received.
