# Troubleshoot Azion Console sign-in

This page covers the symptoms that keep a user out of Azion Console: a lost multi-factor authentication (MFA) device and a lock that Account Lockout Policy applies. An Account owner of the same account restores the access. When the locked-out user is the only Account owner, Azion Support resets the MFA.

---

## The MFA code is unavailable because the device is lost

You cannot sign in because the phone that runs your authenticator application is lost or stolen.

The six-digit MFA code comes from the authenticator application on the device you registered.

- **Ask an Account owner to turn off your MFA**: the Account owner opens **Users Management**, selects your user, turns off the **MFA** switch, and saves. For the procedure, refer to [Multi-factor authentication](/en/documentation/guides/platform/account-and-billing/multi-factor-authentication/).
- **Contact Azion Support when you are the only Account owner**: no other user can reset your MFA, so open a ticket. To open one, refer to [Open a support ticket](/en/documentation/support/open-tickets/).

An Account owner can reset MFA only when MFA enforcement is not mandatory for the users of the account.

After the reset, you sign in to Azion Console without the MFA code.

---

## The user is locked after failed sign-in attempts

You cannot sign in, even with the right password, after several failed attempts.

[Account Lockout Policy](/en/documentation/fundamentals/account-lockout-policy/) locks a user that exceeds the maximum number of failed sign-in attempts. By default, the policy allows 3 attempts and keeps the user locked for 1440 minutes, which is 24 hours.

- **Wait for the blocking period to end**: the user can sign in again after the period the policy sets.
- **Ask an Account owner to unlock the user**: an Account owner can unlock a user before the period ends, through the Azion API. For the procedure, refer to [Unlock a user from Account Lockout Policy](/en/documentation/guides/application-security/access-and-compliance/unlock-account-lockout-policy/).

After the unlock or the end of the period, the user signs in with the right password.

---

## Related resources

- [Users Management](/en/documentation/fundamentals/users-management.md): How an Account owner manages the users of an account and their MFA.
- [Account Lockout Policy](/en/documentation/fundamentals/account-lockout-policy.md): The failed-attempt limit, the blocking period, and the logs the policy writes.
- [Support guidelines](/en/documentation/support.md): The support tiers and the channels that open a ticket.
