Forgotten password and blocked access — what an administrator can and cannot do
There is no self-service “Forgot password” button. An administrator emails the user a new temporary password, but nobody can reset another person’s 2FA because the system has no such mechanism.
Send someone a new password — step by step
An administrator never enters another person’s password. Noxti generates a temporary password and emails it to the user’s address.
- First check Login History for the reason access was denied. Very often it says “account inactive”, not “wrong password” (Live monitor, login history, and activity statistics).
- Go to Configuration → Team & Access → User Accounts.
- Find the person, open the three-dot menu, and choose Edit user.
- Click Send new password. The button is absent if the account has no email address, if you are editing your own account (change your own password under Changing your own password — requirements and when confirmation is needed), or if you are not a company administrator.
- In the Send a new password? dialog, click Send password. The dialog reminds you that a new temporary password will be sent to the user’s address and the current password will stop working immediately.
- If a window asks for a 2FA code, enter it (2FA confirmation when changing permissions).
- You will see New password sent to {address}.
- Tell the employee that their 2FA trust has been cleared on every device and they will need to enter a code the next time they sign in.
If you are denied with a message saying you need company administrator permissions, write access to users alone is not enough; see below.
Forgotten password
There is no “Forgot password” button on the sign-in page. Anyone who has forgotten their password must ask an administrator, who sends a temporary password using Send new password in user editing.
This requires company administrator permissions — write access to users is not enough. This is intentional: sending someone a new password is equivalent to taking over their account.
What happens when you click it:
- Noxti sends “New password for Noxti” with a temporary password. The email also says who reset it and asks the user to contact an administrator if the reset was unexpected.
- The old password stops working immediately.
- An audit log entry records who reset whose password and when.
- All trusted 2FA devices for that person are cleared.
- The new temporary password is valid for 72 hours. If it is not used in that time, it expires and you must send another with the same button.
If the email cannot be sent, the administrator sees an error and the old password stays unchanged.
What the user sees after receiving the password
After signing in with the temporary password, the user is taken to My account → Security, where the Set your own password banner is waiting. Until they change it, they cannot do anything else: they enter the temporary password as the current password and choose their own (Changing your own password — requirements and when confirmation is needed). Any session still using the old or temporary password is also redirected to the password change form.
These messages are visible in the sent-email log, but the password is masked as “••••••••”.
Locked out of 2FA — an administrator cannot unlock it
This is a firm limitation you should know before someone loses their phone:
The system has no way to reset another person’s 2FA. Neither a company administrator nor a superadministrator can turn off someone else’s two-factor authentication. There is no such button or API endpoint.
Only the user themselves can turn off 2FA, by entering their password and a code from their authenticator app or a recovery code.
The practical rule for the whole team is: recovery codes are the only way back in. Everyone who enables 2FA must save them outside the system when they are shown (Two-factor authentication (2FA) — enabling it, backup codes, and disabling it).
If you lose both your phone and recovery codes, contact NOXTI support. A company administrator cannot restore access from this screen.
Accounts a company administrator cannot touch
A company administrator cannot send a new password for, delete, or even search for:
- a platform superadministrator,
- another administrator in the same company.
The same rule covers every field that could be used to take over an account: username, email address, Active switch, and IP restrictions. Each could redirect account recovery to a different address or cut someone off from the system, so none is an ordinary profile edit (Editing a user — details, activity, and IP restrictions).
Other fields in the same form — full name, roles, departments, and warehouses — work normally. Saving the panel without changing any of the four fields above succeeds, even when you are editing another administrator.
The email lookup also reports such an account as non-existent. This is intentional so it cannot be used to find out who is an administrator.
An administrator can always take these actions on their own account.
For companies with only one administrator: have two. A single administrator cannot unlock themselves if they lose access.
Inactive account or wrong password
Login History distinguishes between these cases (Live monitor, login history, and activity statistics). Before resetting a password, check the reason for denial there — quite often the account is simply disabled.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo