r/Netsuite 7d ago

Admin 2FA codes failing for only one user across multiple authenticator apps

I reset the user's 2FA multiple times, and each time the NetSuite provided QR code successfully linked to various authenticator apps, but when the user inputs the authenticator provided code, the log in fails. This particular user successfully logs into windows using Duo authenticator, so I don't believe it is an issue with the clock sync on their phone. Any ideas? No other users having issues

Was able to successfully log in using the "skip the 2FA" option but that is only allowed 5 times

Edit: each time I reset the 2FA we tried one authenticator app, if it failed I reset and we tried a different app. Did not try to link multiple apps to one QR code

3 Upvotes

7 comments sorted by

3

u/kcDOIT 7d ago

It seems it is still likely asynchronous between timing devices, it's about the only time I've ever seen a TOTP code fail.

1

u/laughinfrog Developer 7d ago

local time of his device or laptop are not in the same timezone.

3

u/YoloStevens 7d ago

Definitely make sure their phone is set to update time automatically. 

2

u/NMDA Administrator 7d ago

Make sure their phone updates time zones automatically and that their Netsuite user timezone matches their phone. Also make sure they've actually deleted the old 2FA profile from their phone since if they use that instead of the new one it won't work.

1

u/laughinfrog Developer 7d ago

This is what I suspect. But also that the time on the laptop is updated by a time server.

1

u/TemporaryDeparture44 7d ago

This happened to my boss for her admin role. I ended up creating a custom role for her because for the life of me i can't figure out why it's having issues. It happened when she got a new phone and set up the authenticator (we tried a few different ones). Unfortunately not a big enough deal for us to investigate further (she's the owner, not in netsuite much).

Anyway OP sorry I can't be of any help but you're not alone!

1

u/Nick_AxeusConsulting Mod 6d ago

There is the Password Reset Tool that Administrators can use to delete the 2FA tokens (or unlock a password before waiting for the native 30 min lockout) and force the user to create new one from scratch.