Skip to main content

How to Resolve CTM Login Issues Caused by Multi-Factor Authentication (2FA) (CRM)

If users are unable to log into CTM because they have not completed the two-factor authentication (2FA) setup, a CTM admin can resolve this by resetting or temporarily disabling 2FA for affected users and guiding them through re-enrollment. This guide wal

Before You Begin

Make sure you have the following ready:

  • CTM admin access — you must be logged in as an admin to manage user settings.

  • List of affected users — identify which users are locked out or unable to complete 2FA setup.

  • Affected users should have their CTM username and password available.

  • Affected users will need an authenticator app installed on their phone (e.g., Google Authenticator, Microsoft Authenticator).

  • Affected users should have access to their email in case CTM requires email verification during re-enrollment.

Steps

  1. Log into CTM as an admin.

  2. Navigate to Settings > Users.

  3. Open the profile of each affected user. (Click Edit)

  4. Check the user's two-factor authentication status.

  5. If the user is locked out, reset or temporarily disable 2FA for that user.

  6. Ask the user to log in again using their CTM username and password.
    ​​

  7. Have the user complete the 2FA setup prompt using an authenticator app on their phone.

  8. Save the changes and confirm the user can log in successfully.
    ​​

  9. Repeat these steps for all affected users.

Verification / Expected Result

Once complete, each affected user should be able to log into CTM without issues. They will have successfully re-enrolled in two-factor authentication and can authenticate using their authenticator app going forward.

Troubleshooting / Common Errors

⚠️ User still cannot log in after reset: Confirm the user is entering the correct CTM username and password. If they've forgotten their password, they'll need to complete a password reset before attempting 2FA setup.


⚠️ Authenticator app not working: Ensure the user's phone clock is synced correctly, as authenticator apps rely on accurate time to generate codes. Ask the user to check their phone's date and time settings.


⚠️ All users affected at once: If every user in your organization is locked out due to 2FA, this is likely because 2FA was enabled on the account without users completing the initial setup. Work through each user profile individually using the steps above.


Related Resources

Did this answer your question?