A user account can be in any of the following states:
Registered (Unconfirmed)
The user has successfully signed up, but cannot sign in until the user account is confirmed. The user is enabled but not confirmed in this state.
New users who sign themselves up start in this state.
Confirmed
The user account is confirmed and the user can sign in. When a user enters a code or follows an email link to confirm their user account, that email or phone number is automatically verified. The code or link is valid for 24 hours.
If the user account was confirmed by the administrator or a pre sign-up Lambda trigger, there might not be a verified email or phone number associated with the account.
Password Reset Required
The user account is confirmed, but the user must request a code and reset their password before they can sign in.
User accounts that are imported by an administrator or developer start in this state.
Force Change Password
The user account is confirmed and the user can sign in using a temporary password, but on first sign-in, the user must change their password to a new value before doing anything else.
User accounts that are created by an administrator or developer start in this state.
Disabled
Before you can delete a user account, you must disable sign-in access for that user.