Password and MFA resets without a ticket
"I'm locked out of Okta" is a two-minute fix that often waits hours in a queue. The AI ITSM Agent confirms the person's identity and makes the reset itself.
Last updated 6 October 2026
The problem
Password and MFA resets are frequent, urgent and simple, which makes them a poor use of an IT person's time and a frustrating wait for the employee.
They are also a favourite route for social engineering, so the identity check matters more than the reset itself.
How the AI ITSM Agent does it
- 01
The employee asks in Slack
"I'm locked out" or "I got a new phone and lost my MFA."
- 02
It confirms who they are
It matches the Slack account to the person in your identity provider. A self-typed email is never enough to authorise a reset.
- 03
It makes the change
It resets the password, clears the MFA factor or unlocks the account in Okta, following your rules for each.
- 04
It replies and records
The employee gets the next steps in the thread, and the reset is written to the activity record.
Example
Guardrails
- Resets only for a verified identity; unverified requests go to a person.
- Your rules decide which resets need an approver, for example for admins.
- Every reset is recorded with who asked and what changed.
Questions
How does it stop someone pretending to be a colleague?
It only acts on a Slack account that is linked to the person in your identity provider. If the link can't be confirmed, the request goes to your IT team.
Can admins reset their own MFA this way?
That's your call. Many teams require an approver for admin accounts; the rule is set once and applied every time.
Related
Hire your first AI employee
Tell us which team needs one, and we'll show you how it works with your tools.
