Submitting forms on the support site are temporary unavailable for schedule maintenance. If you need immediate assistance please contact technical support. We apologize for the inconvenience.
OneLogin - OneLogin Protect MFA (auth factor) cannot be used after the user changed or updated his device
Description
A user changed to a new mobile device and was unable to access previously configured multi-factor authentication (MFA) accounts in the OneLogin Protect app after transferring his apps from the old phone to the new phone with a backup/restore procedure . The expectation was that existing MFA factors or authenticator entries could be transferred or restored to the new device.
Additionally, there was uncertainty about whether logging in on the new device would automatically restore or migrate existing MFA configurations.
Cause
OneLogin Protect does not currently support backing up or restoring MFA configurations across devices.
MFA factors consist of two components:
A registration stored in the OneLogin tenant
A local configuration on the mobile device
If the original device is lost or erased, or the factor (user account) is removed, any locally stored authenticator data is permanently lost.
The technical documentation confirms that when a new device is introduced, the authentication factor must be set up again, as device registration is required per device.
Resolution
To restore access and reconfigure MFA on a new device, a user needs to:
Ensure he can authenticate with an alternative factor (e.g., SMS, e-mail, another authenticator app, the old device OL Protect app if still available, or ask the Help Desk for a temporary OTP).
Once logged in, go to the User Profile in the OneLogin portal's top-right corner picture.
Navigate to the Security Factors tab.
If the Policy allows, select Add Factor and choose OneLogin Protect.
Scan the QR code with the new phone using the OneLogin Protect app.
Verify the new factor is functioning correctly.
Remove any outdated or unused device registrations from the user profile.
Notes:
Any MFA entries that existed only on the previous device must be manually reconfigured.
Administrators are advised to configure user policies that allow multiple authentication factors (or at least two) to prevent lockout scenarios.
Additional Information
Authenticating With OneLogin Protect >> https://onelogin.service-now.com/support?id=kb_article&sys_id=77ff265d97d4e6900f94b86ef053af7c
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Recommended Content
Product(s):
OneLogin
Hosted
Topic(s):
How To
Article History:
Created on: 5/22/2026 Last Update on: 6/12/2026
Thank you for your feedback for Topic Request
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Welcome to One Identity Support
You can find online support help for*product* on an affiliate support site. Click continue to be directed to the correct support content and assistance for *product*.
The One Identity Portal no longer supports IE8, 9, & 10 and it is recommended to upgrade your browser to the latest version of Internet Explorer or Chrome.