Recovery Codes
When two factor is set up for a user, they are provided 8 emergency recovery codes which can be used if their authenticator app is unavailable.
If a recovery code is used, that code is removed from the user's account, and replaced with a fresh code. When this happens, the user will be notified via email.
They will be directed to their profile where they can "Show recovery codes" to see all existing recovery codes.
If needed, the user can also re-generate their codes to get 8 new codes.
Admin cannot see or reset a user's recovery codes. Only the logged in user has access to these functions.