> For the complete documentation index, see [llms.txt](https://docs.gxc.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gxc.io/docs/application-notes/4g-and-5g-onyx-portal-mfa.md).

# 4G & 5G Onyx Portal MFA

## Introduction

Multi-factor Authentication (MFA), also known as Two-Factor Authentication (2FA), is a layered approach to securing your Onyx Portal user account. Your Onyx Portal user ID/password is the first factor of authentication. A Time-based One-time Password (TOTP) generated by an authenticator app installed on your mobile phone is the second factor of authentication.

{% hint style="info" %}
NOTE: MFA is enabled system-wide for all Onyx Portal users and cannot be disabled.
{% endhint %}

{% hint style="info" %}
NOTE: If you log on to the Onyx Portal using your customer organization’s SSO credentials, you must follow your organization’s MFA requirements.
{% endhint %}

**MFA workflow:**

1. Install an authenticator app on your mobile phone. See [Install Authenticator App](#install-authenticator-app).
2. Log on to the Onyx Portal and activate your MFA. See [Activate Your MFA](#activate-your-mfa).
3. Whenever you log on to the Onyx Portal, use the current MFA OTP displayed in your authenticator app as your second factor of authentication. See [Log On to the Onyx Portal](#log-on-to-the-onyx-portal).
4. If your mobile phone is compromised or lost, or your MFA backup codes are unavailable or exhausted, reset your MFA secrets. See [Reset Your MFA Secrets](#reset-your-mfa-secrets) or [As Administrator Reset Onyx Portal User’s MFA Secrets](#as-administrator-reset-onyx-portal-users-mfa-secrets).

## Set Up MFA

To set up your MFA, you must have an authenticator app such as Google Authenticator, Microsoft Authenticator, or Duo Mobile installed on your mobile phone. If you don't already have one installed, proceed to the [Install Authenticator App](#install-authenticator-app) section. If you already have one installed, proceed to the [Activate Your MFA](#activate-your-mfa) section.

### Install Authenticator App

To activate and use MFA, you must install an authenticator app on your mobile phone. Any authenticator app that generates TOTPs using the standard “HMAC-based One-time Password” (HOTP) algorithm—such as Google Authenticator, Microsoft Authenticator, or DUO Mobile—can be used. The authenticator app generates the TOTPs used as the second factor of authentication. This document describes how to use the Google Authenticator app, which is available for Android on the Google Play Store and for iPhone on the App Store.

### Activate Your MFA

{% hint style="info" %}
NOTE: Activating your MFA is a one-time procedure.
{% endhint %}

**To activate your MFA:**

{% stepper %}
{% step %}
Using a supported web browser visit [https://portal.gxc.io](https://portal.gxc.io/).

The Onyx Portal Login page is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FVfkOdALKb4FWffKosCRM%2Fimage.png?alt=media&amp;token=b25183f2-7427-4fcd-93b0-69603b264395" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter the following details, then click **Login**:

* **Email** – (Required) Your Onyx Portal logon ID (email address).

The GXC IdP Login page is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FXQQjQGbpA7yNsV7Z5rF6%2Fimage.png?alt=media&amp;token=d242118a-fd0d-4dc5-b704-dfa62cd66663" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter the following details, then click **Login**:

* **Username** – (Required) Your Onyx Portal username (email address).
* **Password** – (Required) Your Onyx Portal password.
* **I’m not a robot** – (Displayed only if you fail a login attempt. Required.) Select to validate reCAPTCHA—a seamless fraud detection service that stops bots and other automated attacks by rate-limiting log on attempts while allowing valid users.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>NOTE: The I’m not a robot checkbox for reCAPTCHA validation is displayed only if you fail an Onyx Portal login attempt. For example, when you enter an incorrect username or password. The Activate Multi-Factor Authentication dialog box is displayed.</p></div>

  The **Activate Multi-Factor Authentication** dialog box is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FymKoij4qlj9BpnsIVQpF%2Fimage.png?alt=media&amp;token=1da76cfa-1393-477b-bc54-6d90b86924cb" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
On your mobile phone, open the authenticator app and scan the QR code displayed in the Onyx Portal > **Activate Multi-Factor Authentication** dialog box > **QR Code** section.

For example, if you are using the Google Authenticator app:

* If it is your first time setting up MFA in the app, click **Scan a QR code**.
* If you have previously set up other MFA in the app, click > **Scan a QR code**.
* If you are unable to scan the QR code, click **Enter a setup key**, then manually enter the alphanumeric key displayed in the Onyx Portal > **Activate Multi-Factor Authentication** dialog box > **Setup Key** section.

  To copy the setup key to your clipboard, click <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FYGqzYy6dwJW5j3cCSDDG%2Fimage.png?alt=media&amp;token=039db3fa-db5e-4cd5-bddd-c081e0d72f78" alt="" data-size="line"> (copy).

  <figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FmmZAt3N592JtRgBavgbE%2Fimage.png?alt=media&amp;token=35802d3e-0b5a-449c-9fbb-f54134ff73e6" alt=""><figcaption></figcaption></figure>

  <figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FwOGiCSdl9HhUvW3ERrTZ%2Fimage.png?alt=media&amp;token=c26db727-b347-4685-823f-46e11790afe1" alt=""><figcaption></figcaption></figure>

  The authenticator app displays a six-digit OTP.

  This indicates you have successfully activated your MFA.

  Hereon, every time you log in to the Onyx Portal, you must use the current OTP displayed in your authenticator app as your second factor of authentication.
  {% endstep %}

{% step %}
Save your MFA backup codes to a safe location.

After activating your MFA, whenever you log on to the Onyx Portal, if you are unable to obtain an OTP from the authenticator app, instead of an OTP, you can use one of the backup codes as your second factor of authentication. For more information, see [MFA Backup Codes](#mfa-backup-codes).

To save your MFA backup codes as a text file, in the Onyx Portal > **Activate Multi-Factor Authentication** dialog box > **Backup Codes** section > click ![](https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FuDpsbOr8D8Ghw1onEFKf%2Fimage.png?alt=media\&token=62d2e6f8-175e-4310-9142-4a04d01d111d) (download).

{% hint style="info" %}
NOTE: If you do not download your backup codes before you confirm your MFA activation (Step 6), a text file containing your MFA backup code is automatically downloaded to your computer. In your Downloads folder look for the most recent text file with the name format “OnyxPortal\_BackupCodes\_\_\<date\_timestamp>.txt”.
{% endhint %}
{% endstep %}

{% step %}
Confirm your MFA is activated (Step 4).

You can log on to the Onyx Portal up to five times without activating your MFA (Step 4). To skip activating your MFA (Step 4), click **Skip**. After you exhaust your five grace logins, to access the Onyx Portal you must activate your MFA.

To confirm your MFA is activated (Step 4), click **Confirm MFA OTP**. The **Confirm MFA OTP** dialog box is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FXpqkleFx3SRTDqNISIDK%2Fimage.png?alt=media&amp;token=ada7169d-bce5-4909-88bc-98148477bfb8" alt="" width="269"><figcaption></figcaption></figure>

Enter the MFA OTP displayed in the authenticator app on your mobile phone and click **Submit**.

The Onyx Portal Dashboard page is displayed.
{% endstep %}
{% endstepper %}

## Log On to the Onyx Portal

You can log on to Onyx Portal only if you have an Onyx Portal user account, or if SSO authentication is supported for your customer organization (i.e., your organization’s IdP is integrated with the Onyx Portal/Onyx IdP).

For information on how to log on with your Onyx Portal credentials, see [Log On Using Your Onyx Portal Credentials](#log-on-using-your-onyx-portal-credentials).

For information to log on with your customer organization’s SSO credentials, see [Log On Using Your Organization’s SSO Credentials](#log-on-using-your-organizations-sso-credentials).

### Log On Using Your Onyx Portal Credentials

{% hint style="info" %}
NOTE: Before you can log on to the Onyx Portal for the first time, you must activate your Onyx Portal user account. For more information, refer to Onyx Portal Operations Guide > Getting Started > Activate Your Onyx Portal User Account.
{% endhint %}

**To log on to the Onyx Portal using your Onyx Portal credentials:**

{% stepper %}
{% step %}
Using a supported web browser visit [https://portal.gxc.io](https://portal.gxc.io/).

The Onyx Portal Login page is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FB54lBx3tlcpbfKKPY1aP%2Fimage.png?alt=media&amp;token=85f48aea-2d50-4897-b140-381e6f628ac2" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter the following details, then click **Login**:

* **Email** – (Required) Your Onyx Portal logon ID (email address).

The IdP Login page is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FDNn19K1mypn4xskcZ2et%2Fimage.png?alt=media&amp;token=ea728da9-0c38-49a0-bbe9-0ddaa4bcdb2f" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter the following details, then click **Login**:

* **Email** – (Required) Your Onyx Portal username (email address).
* **Password** – (Required) Your Onyx Portal password.
* **I’m not a robot** – (Displayed only if you fail a login attempt. Required.) Select to validate reCAPTCHA—a seamless fraud detection service that stops bots and other automated attacks by rate-limiting log on attempts while allowing valid users.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>NOTE: The <strong>I’m not a robot</strong> checkbox for reCAPTCHA validation is displayed only if you fail an Onyx Portal login attempt. For example, when you enter an incorrect username or password. </p></div>

  The 2FA page is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FWJuHpk7xsNxQGzqMqIGy%2Fimage.png?alt=media&amp;token=1625aca5-c782-4b53-8410-26a2f0c9ee16" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter the six-digit MFA OTP displayed in the authenticator app on your mobile phone, then click **Login**.

You are logged on to the Onyx Portal, and the Dashboard page is displayed.

{% hint style="info" %}
NOTE: The six-digit OTP refreshes every 30 seconds and is valid only for one minute.
{% endhint %}

{% hint style="info" %}
NOTE: If your mobile phone is not accessible or you are unable to obtain an MFA OTP, instead of an MFA OTP you can pro tem use an MFA backup code to authenticate your Onyx Portal logon. For more information, see [MFA Backup Codes](#mfa-backup-codes).
{% endhint %}

{% hint style="info" %}
NOTE: If you are unable to obtain MFA OTPs to log in to the Onyx Portal and you have exhausted your MFA backup codes, you will have to create a support ticket to contact GXC Technical Support for assistance. When the message “You have exhausted your MFA backup codes. Please contact GXC Technical Support for assistance.” is displayed, click the “Technical Support” link to enter the “Onyx Support Portal” and create the support ticket. You are logged on to the Onyx Portal, and the Dashboard page is displayed.
{% endhint %}
{% endstep %}
{% endstepper %}

### Log On Using Your Organization’s SSO Credentials

{% hint style="info" %}
NOTE: If you log on to the Onyx Portal using your customer organization’s SSO credentials, you must follow your organization’s MFA requirements.
{% endhint %}

{% hint style="info" %}
NOTE: To use SSO authentication, your organization’s IdP must be integrated with the Onyx IdP. In this case, the user accounts exist in the customer IdP and are authenticated by the customer IdP.
{% endhint %}

**To log on to Onyx Portal using your organizational SSO credentials:**

{% stepper %}
{% step %}
Using a supported web browser visit [https://portal.gxc.io](https://portal.gxc.io/).

The Onyx Portal Login page is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FWx7v3AcmFpdRwewOgOT3%2Fimage.png?alt=media&amp;token=9ad38881-d319-46b7-bfd6-731c3ccd13a6" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Click the **Sign in to an Organization** link.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FbUWi9yxqy4bHEJ6FZWbB%2Fimage.png?alt=media&amp;token=e1411405-e4cb-46d5-a58e-082f8880f7b1" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter the following details, then click **Login**:

* **Organization Name** – (Required) Your organization’s name.

Contact your Onyx Portal administrator for the organization name to use.

{% hint style="info" %}
NOTE: The Organization Name field is case-sensitive. Your organization’s IdP login page is displayed.
{% endhint %}

Your organization’s IdP login page is displayed.
{% endstep %}

{% step %}
Enter the authentication information required by your organization’s IdP and continue as instructed.

You are logged on to the Onyx Portal, and the Dashboard page is displayed.
{% endstep %}
{% endstepper %}

## MFA Backup Codes

After activating your MFA, if your mobile phone is unavailable or you are unable to obtain an OTP from the authenticator app, instead of an OTP, you can pro tem use a backup code as your second factor of authentication.

{% hint style="info" %}
NOTE: You must make sure to save your backup codes that are displayed when you activate your MFA or whenever you reset your MFA secrets. For more information, see [Activate Your MFA ](#activate-your-mfa)and [Reset Your MFA Secrets ](#reset-your-mfa-secrets)respectively.
{% endhint %}

{% hint style="info" %}
NOTE: Only if you have saved the backup codes that were generated when you activated your MFA or last reset your MFA secrets, whichever is recent, can you use the backup codes.
{% endhint %}

{% hint style="info" %}
NOTE: The MFA backup codes are single use only and cannot be reused.
{% endhint %}

{% hint style="info" %}
NOTE: If you have not saved your backup codes, or if you have exhausted all your backup codes, you can reset your MFA secrets to generate a new set of backup codes. For more information, see [Reset Your MFA Secrets](#reset-your-mfa-secrets).
{% endhint %}

{% hint style="info" %}
NOTE: When you reset your MFA secrets, any previous backup codes will become invalid.
{% endhint %}

{% hint style="info" %}
NOTE: If you are unable to obtain MFA OTPs to log in to the Onyx Portal and have exhausted your MFA backup codes, you will have to create a support ticket to contact GXC Technical Support for assistance. When the message “You have exhausted your MFA backup codes. Please contact GXC Technical Support for assistance.” is displayed, click the “Technical Support” link to enter the “Onyx Support Portal” and create the support ticket.
{% endhint %}

## Reset Your MFA Secrets

If your mobile phone is compromised or lost, or your MFA backup codes are unavailable or exhausted, you must reset your MFA secrets. Resetting your MFA secrets is equivalent to deleting your MFA registration, allowing you to set up your MFA again as if you are a new user.

**To reset your MFA secrets:**

{% stepper %}
{% step %}
In the upper-right corner of the Onyx Portal GUI, click the current Onyx Portal account’s name, then click **Reset MFA Secrets**.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FsXSth0fgDaExjIKKGyfh%2Fimage.png?alt=media&amp;token=ef9d83c2-7e19-409b-b07a-dfccc7b26a45" alt="" width="231"><figcaption></figcaption></figure>

{% hint style="info" %}
NOTE: The **Reset MFA Secrets** option is enabled only if you have already activated your MFA. For more information, see [Activate Your MFA](#activate-your-mfa).
{% endhint %}

The **Reset MFA Secrets** confirmation box is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F0OFNWvS1ybACu5CikpHv%2Fimage.png?alt=media&amp;token=426d13db-c669-4857-b1b5-552636ff847e" alt="" width="299"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
To confirm you want to reset your MFA secrets, click **Yes**.

The **Reset MFA Secrets** dialog box is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FLerMe2vuvgqb5IQHG0bX%2Fimage.png?alt=media&amp;token=705d2314-901b-41e8-abd2-cd245c1d9ae1" alt="" width="563"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
On your mobile phone, open the authenticator app and scan the QR code displayed in the Onyx Portal > **Reset MFA Secrets** dialog box > **QR Code** section.

For example, if you are using the Google Authenticator app:

* If it is your first time setting up MFA in the app, click **Scan a QR code**.
* If you have previously set up other MFA in the app, click <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FVSxlIH9m3l0BSFmRT5xX%2Fimage.png?alt=media&amp;token=ba0d9675-1dca-457e-9d69-a64ec894aeb8" alt="" data-size="line"> > **Scan a QR code**.
* If you are unable to scan the QR code, click **Enter a setup key**, then enter the alphanumeric key displayed in the Onyx Portal > **Reset MFA Secrets** dialog box > **Setup Key** section.

  To copy the setup key to your clipboard, click <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FTQdK6Ren95yxuthviZDr%2Fimage.png?alt=media&amp;token=3743805b-3809-4f1b-b1cc-5a0d34ef165a" alt="" data-size="line"> (copy).

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F0n5cP1CxS4qgqQpZrb17%2Fimage.png?alt=media&amp;token=1268efb1-9723-4058-8c5a-d8231440869f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FzQattwkuzuxW7EGhnQY9%2Fimage.png?alt=media&amp;token=30f0ea4d-7312-4eb8-8cf2-0b21578e9d39" alt=""><figcaption></figcaption></figure>

The authenticator app displays a six-digit OTP.

This indicates you have successfully reset your MFA secrets.

Hereon, every time you log in to the Onyx Portal, you must use the current OTP displayed in your authenticator app as your second factor of authentication.
{% endstep %}

{% step %}
Save your MFA backup codes to a safe location.

Whenever you log on to the Onyx Portal, if you are unable to obtain an OTP from the authenticator app, instead of an OTP, you can use one of these backup codes as your second factor of authentication. For more information, see [MFA Backup Codes](#mfa-backup-codes).

To save your MFA backup codes as a text file, in the Onyx Portal > **Reset MFA Secrets** dialog box > **Backup Codes** section > click <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FRuvqsRia6kuyJRpvptNN%2Fimage.png?alt=media&amp;token=88c3f878-5275-44d1-8622-e6b5aa9f3e7b" alt="" data-size="line"> (download).

{% hint style="info" %}
NOTE: When you reset your MFA secrets, any previous backup codes will become invalid.
{% endhint %}

{% hint style="info" %}
NOTE: If you do not download your backup codes before you close the Reset MFA Secrets dialog box, a text file containing your MFA backup codes is automatically downloaded to your computer. In your Downloads folder, look for the most recent text file with the name format “OnyxPortal\_BackupCodes\_\_*\<date\_timestamp>*.txt”.
{% endhint %}
{% endstep %}

{% step %}
To confirm your MFA secrets are reset (Step 3), click **Confirm MFA OTP**.

The **Confirm MFA OTP** dialog box is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F7p92EV2CsFbljAajal6i%2Fimage.png?alt=media&amp;token=3b838704-2dee-40f1-a5dd-4ae60fa93fd4" alt="" width="308"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Enter the MFA OTP displayed in the authenticator app on your mobile phone and click **Submit**.
{% endstep %}

{% step %}
The next time you log on to the Onyx Portal, after your user ID/password is authenticated, the **2-Factor Authentication OTP** dialog box is displayed. Enter the current OTP displayed in your authenticator app, then click **Login**.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fy8KjGFQqCJ4HJLv3KR6L%2Fimage.png?alt=media&amp;token=bc1b0e60-df84-411c-b707-bf1e953ce0d5" alt=""><figcaption></figcaption></figure>

After the OTP is authenticated, you are logged in to the Onyx Portal, and the Dashboard page is displayed.
{% endstep %}
{% endstepper %}

## As Administrator Reset Onyx Portal User’s MFA Secrets

If a user’s mobile phone is compromised or lost, and the user’s MFA backup codes are unavailable or exhausted, you can reset the user’s MFA secrets. Resetting a user’s MFA secrets is equivalent to deleting the user’s MFA registration, allowing the user to set up MFA again as if for a new user.

{% hint style="info" %}
NOTE: You can reset another Onyx Portal user’s MFA secrets only if you are a GXC Administrator, GXC Partner Administrator, or a Super Administrator.
{% endhint %}

{% hint style="info" %}
NOTE: If a user does not have access to his/her phone temporarily, the user can use their backup codes to log in. For more information, see Reset Your MFA Secrets.
{% endhint %}

**To reset a user’s MFA secrets:**

{% stepper %}
{% step %}
Switch to the required customer account.

To switch between Onyx Portal accounts, in the upper-right corner of the page, click the current Onyx Portal account’s name, then select the required account.
{% endstep %}

{% step %}
In the navigation pane, click **Administration** > **Users** tab.

The **Administration** page > **Users** tab displays the list of active user accounts.
{% endstep %}

{% step %}
For the user account that you want to reset MFA secrets, in the **Actions** column, click the corresponding ⋮ (options) icon, then click **Reset MFA Secrets**.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FAGek6XMqBx3zjwm1KFoi%2Fimage.png?alt=media&amp;token=06ee8672-bccc-4223-85f2-c00762139624" alt="" width="127"><figcaption></figcaption></figure>

The **Reset MFA Secrets** confirmation dialog box is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FcSyyNG3mULkgZTzOlPxI%2Fimage.png?alt=media&amp;token=986b0c6c-4e7d-42bf-b73a-ab51d34643bd" alt="" width="333"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
To confirm resetting the user’s MFA secrets, click **Yes**.
{% endstep %}
{% endstepper %}

## Related Documentation

* *4G & 5G Onyx Portal Integration with Customer IdP Application Note*
* *GXC Glossary*

## Contact GXC

To get in touch with GXC, please visit <https://gxc.io/contact-us/>.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.gxc.io/docs/application-notes/4g-and-5g-onyx-portal-mfa.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
