# OTP Authentication after Password reset

**URL:** <https://forum.keycloak.org/t/otp-authentication-after-password-reset/12721>\
**Category:** Getting advice\
**Created:** [December 21, 2021, 9:44am UTC](https://forum.keycloak.org/t/otp-authentication-after-password-reset/12721 "2021-12-21T09:44:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vmrz](https://avatars.discourse-cdn.com/v4/letter/v/df705f/32.png) [@vmrz](https://forum.keycloak.org/u/vmrz)\
**Post date:** [December 21, 2021, 9:44am UTC](https://forum.keycloak.org/t/otp-authentication-after-password-reset/12721/1 "2021-12-21T09:44:27Z")

</div>

Hello !

By default, Keycloak automatically logs in the user after performing a password reset flow.

If the user has prevously configured an OTP, I would like to ask for OTP authentication after the user has reset his password (and so to prevent the automatic login):

1. The user clicks on “I forgot my password” link
2. The user submits his username or email address
3. The user receives an email and clicks on the link
4. The user submits his new password
5. If the user has previously configured an OTP:

- Ask for OTP Authentication

1. The user is authenticated

I tried to play with the Authentication flows, but the OTP form is always shown before the password change form during the process:

 ![password_reset_flow_with_otp](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/b/b79cd612d79c7ec591cd451f771262ba9abb4c1f.png)

I hope one of you can help me solve that 🙂

Thank you very much !

---

<div class="post-metadata">

**Author:** ![vmrz](https://avatars.discourse-cdn.com/v4/letter/v/df705f/32.png) [@vmrz](https://forum.keycloak.org/u/vmrz)\
**Post date:** [December 24, 2021, 8:53am UTC](https://forum.keycloak.org/t/otp-authentication-after-password-reset/12721/2 "2021-12-24T08:53:01Z")

</div>

Hello again 🙂

Can anybody help me on that issue ?

Thank you very much !

---

<div class="post-metadata">

**Author:** ![vmrz](https://avatars.discourse-cdn.com/v4/letter/v/df705f/32.png) [@vmrz](https://forum.keycloak.org/u/vmrz)\
**Post date:** [January 19, 2022, 7:37am UTC](https://forum.keycloak.org/t/otp-authentication-after-password-reset/12721/3 "2022-01-19T07:37:15Z")

</div>

Hello again !

I am still struggling on that issue 🙂 Hopefully someone can help me on that.

From my point of view, it is a security issue because MFA is not required after a password reset (if the user has configured one).

If an attacker gains access to the password reset link, the legitimate user is not protected with his configured MFA

Thank you very much !.

---

<div class="post-metadata">

**Author:** ![moritzschmitz-oviva](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/moritzschmitz-oviva/32/9480_2.png) [@moritzschmitz-oviva](https://forum.keycloak.org/u/moritzschmitz-oviva)\
**Post date:** [May 17, 2024, 1:07pm UTC](https://forum.keycloak.org/t/otp-authentication-after-password-reset/12721/4 "2024-05-17T13:07:36Z")

</div>

We ran into the same issue now. Surprised this is the default setup.

It allows an attacker to add their own OTP device, breaking its security.
