# Disabling OTP setup with "Forgot Password" / Reset Credentials flow

**URL:** <https://forum.keycloak.org/t/disabling-otp-setup-with-forgot-password-reset-credentials-flow/3204>\
**Category:** Configuring the server\
**Tags:** authentication\
**Created:** [June 8, 2020, 3:01pm UTC](https://forum.keycloak.org/t/disabling-otp-setup-with-forgot-password-reset-credentials-flow/3204 "2020-06-08T15:01:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shred](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/shred/32/970_2.png) [@shred](https://forum.keycloak.org/u/shred)\
**Post date:** [June 8, 2020, 3:01pm UTC](https://forum.keycloak.org/t/disabling-otp-setup-with-forgot-password-reset-credentials-flow/3204/1 "2020-06-08T15:01:57Z")

</div>

New to keycloak but I noticed the default settings with keycloak is to force an MFA/OTP reset when a user goes through the Forgot Password (Reset Credentials) flow. I’d like to change it so when a user does this, it only asks them to reset their password but not the MFA/OTP token.

The documentation covers this [here](https://www.keycloak.org/docs/latest/server_admin/#forgot-password) but the recommendation to disable this behavior is:

> If you do not want OTP reset, then just chose the `disabled` radio button to the right of `Reset OTP` .

My question is, couldn’t I just choose `disabled` for `Reset Conditional - OTP`? I’m not sure if there would be any other side effects or differences from the two options.

 ![reset-credentials-flow](https://global.discourse-cdn.com/free1/uploads/keycloak/original/1X/98677eb2d5a7da934022e22e71f4dfcc87c51d32.png)

Red is what the documentation recommends. Blue is what I’m wondering if it will work, or deleting `Reset - Conditional OTP` altogether. I guess I’m not following what the purpose of `Reset - Conditional OTP` would be with `Reset OTP` set to `disabled`.

---

<div class="post-metadata">

**Author:** ![shred](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/shred/32/970_2.png) [@shred](https://forum.keycloak.org/u/shred)\
**Post date:** [June 9, 2020, 3:19am UTC](https://forum.keycloak.org/t/disabling-otp-setup-with-forgot-password-reset-credentials-flow/3204/2 "2020-06-09T03:19:59Z")

</div>

Reading the example of the browser authentication flow example in the docs makes me further think what I mentioned above, I think `Reset - Conditional OTP` is essentially doing nothing if the only condition, `Reset OTP`, is disabled:

> 1. The second execution in the Forms sub-flow is a new sub-flow: the `Browser - Conditional OTP` sub-flow. Since this sub-flow is _conditional_ , whether it is executed depends on the result of the evaluation of the `Condition - User Configured` execution. If it is, the executions for this sub-flow are loaded and the same processing logic occurs
> 2. The next execution is the `Condition - User Configured` . This checks if the other executions in the flow are configured for the user. Meaning that the `Browser - Conditional OTP` sub-flow will only be executed if the user has an OTP credential configured.
> 3. The final execution is the `OTP Form` . This is marked as _required_ , but because of the setup in the _conditional_ subflow, it will only be run if the user has an OTP credential set up. If he doesn’t, the user will not see an OTP form.

---

<div class="post-metadata">

**Author:** ![Nandika](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/nandika/32/3113_2.png) [@Nandika](https://forum.keycloak.org/u/Nandika)\
**Post date:** [May 7, 2021, 3:49pm UTC](https://forum.keycloak.org/t/disabling-otp-setup-with-forgot-password-reset-credentials-flow/3204/3 "2021-05-07T15:49:26Z")

</div>

I could fix this way.

**Step 1** : Create a new ‘Reset Credentials’ flow (copy from existing flow)

**Step 2** : Add new execution ‘OTP Form’ (refer the image below)

 ![reset pwd OTP flow](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/d/d20080a25d34d5b7e4fe184ccbc42e1fc07ee7b5.jpeg)

**Step 3** : Bind new reset credential flow into Authentication \>\> Bindings \>\> Reset Credentials

**Expected flow:**

1. OTP required for MFA enabled users prior to load reset password page
2. OTP should not reset after change the password
3. Load reset password page for None MFA users (OTP page load not required)

Hope this solves your problem.

---

<div class="post-metadata">

**Author:** ![chloesoe](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/chloesoe/32/1700_2.png) [@chloesoe](https://forum.keycloak.org/u/chloesoe)\
**Post date:** [May 30, 2022, 9:12am UTC](https://forum.keycloak.org/t/disabling-otp-setup-with-forgot-password-reset-credentials-flow/3204/4 "2022-05-30T09:12:39Z")

</div>

thanks @Nandika that was exactly what I was looking for.

---

<div class="post-metadata">

**Author:** ![MartinH](https://avatars.discourse-cdn.com/v4/letter/m/848f3c/32.png) [@MartinH](https://forum.keycloak.org/u/MartinH)\
**Post date:** [July 2, 2022, 5:26pm UTC](https://forum.keycloak.org/t/disabling-otp-setup-with-forgot-password-reset-credentials-flow/3204/5 "2022-07-02T17:26:51Z")

</div>

Actually, this only enforces OTP for users that have been configured before, i.e. users that have initially set up an OTP.

If you want to enforce OTP for all users, regardless if they have been configured or not (which effectively disables “reset password” for non configured users, which is what I was looking for), you have to use this flow instead:

 ![enforce OTP](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/2/2803af5e9f50e0af40c731e92e7d61bb62bc138c.png)

Greetings,  
Martin
