Troubleshooting Evo Authenticator Mobile App Issues
This article serves as a way for you to self-serve your users without needing to reach out to Evo for resetting user's security questions, or other mobile issues. However, if you do find yourself in a situation where you need assistance, do not hesitate to reach out!
Always make sure that you have the latest version of the Evo Authenticator App from your appropriate App Store!
Potential issues:
- Users forgot security questions.
- Cannot setup MFA for the first time due to security questions errors or other reasons.
- Keys are shown as inactive (User disabled in the portal)
- Users change/lost their phones and cannot re-setup a new phone (related to security questions).
If users are experiencing issues on an existing account, have the user retrieve their QR code (either from the portal or a Welcome Email) from their Main Evo Key (Will be the first key on their list of keys unless it was manually re-arranged. The key also will not be able to be deleted from the selection screen) to re-scan into their account. This will preserve their existing keys.
Resetting Security Questions
Evo now gives admins the ability to reset the Evo Mobile App Security Questions and Answers! If you have a user who does not remember their security answers or for any other reason, you can now reset this for them within their User Details.
DO NOTE: There is a new role that must be enabled for the administrative user under Role-Based Permissions in order to access and use the feature. It is located under Users, titled Reset Security Questions. Global admins do not require this role to be enabled. Refer to the screenshot below.

Resetting the Security Questions
- Log into your Evo Portal as an Administrative user (url.evosecurity.com)
- Click on "My Company" or locate the Customer you would like to view
- Click on the "People" tab.
- Locate the user that would like security questions reset and click on the e-mail of that user to view the User Details page.
- On the user details page, you'll notice a new button available for you to interact with

Click on this button, accept the confirmation dialog box, and the user's security questions and answers will be reset!
NOTE: If your 3rd party keys do not appear after a Security Question reset and install, please uninstall the Mobile app once more. Re-download the app, re-scan the key, then answer those new security questions you just created. Your 3rd party keys should now appear.
Using the Evo Mobile App
After the security questions and answers have been reset, the user must perform additional steps from their end in order to be properly set up once more:
- Have the user uninstall the Evo Mobile App
- Once uninstalled, have the user download and re-install the Evo Mobile App
- Once re-installed, have the user scan the QR code once more
- This should prompt the user to create new security questions and answers!
If that doesn't work and the user doesn't have any other keys associated with the account, you can proceed to the following steps:
Remove device(s) from user account
- Force close the Evo app
- Navigate to Evo portal > Tenant > People > Select the users > Devices.
- Select device(s) and remove it.
- Re-open the Evo app
- Resend the QR code to user and have the user to scan it.
- If that doesn't work, repeat the steps but have the user to uninstall the Evo Authenticator app as opposed to force closing the app

Remove/re-sync user from Evo portal and uninstall/re-install Evo Authenticator mobile app.
1. Remove the user from the Evo Sync group (the group name could be different on your AD). Open "Active Directory Users and Computers" tool on your on-prem AD, navigate to the user and open user's properties.

2. You can wait for the LDAP agent syncs after 10 minutes or force it to sync by open LDAP Agent Setting app from your Start Menu. NOTE: This requires a more recent/latest version of the LDAP agent. If your LDAP agent does not have this feature, do please generate and download a more current version of the LDAP agent from the Evo Portal.

3. Uninstall/re-install Evo Secure Login to make sure it does not have any cache on it.
Note for Azure AD: If you use Azure AD to sync users, then you can go to Azure AD portal to remove user from the sync group. Wait for Azure AD to fully remove user(s), then re-add them back to the sync group. This process can take up to 30-60 minutes since Azure AD takes time to sync.
3. After re-adding users back to the Evo portal, you can send a new QR code to the user's email or alternative email address. Then the user(s) can scan a QR code and setup security questions.
Does it effect end-users?
Since Evo does not save/store any end-user data, it's safe to remove/re-add users as needed. End-users only need to re-setup their MFA and security questions. Secure Login, SSO or Radius services still work as before.
What if the users are IT technicians or IT admins who have permissions and Elevated Access attached to their accounts?
You will need to re-setup their permissions and/or Elevated Access OR you can submit a request to reset their security questions to support@evosecurity.com. Evo support will ask the requester to answer a security question to verify it's a legitimate account.