The procedure to remove all E-SSO data for a specific user is the following:
In Active Directory mode:
Erase following LDAP objects under the concerned user:
CN=OTP if it exists
All other CN sub-objects containing parameters with a name beginning with enatel.
If using ADUC ensure View | User, Contacts & Groups and Computer as Containers is enabled
In ADAM mode:
In the AD find the UID of the concerned user
In ADAM find the CN=<user_uid> entry under the CN=WiseGuardForeignObjects tree and delete it (CN=<user_uid>).