GuideHQ

What do I do if I lose my two-factor device?

The ten minutes of preparation that prevents this, and what to do if you are already locked out.

Difficulty
beginner
Time
45 min
Read
2 min
Safety
caution

Short answer

Use your backup codes — they were shown when you enabled two-factor and most people saved them somewhere. If you do not have them, the account recovery process is your only route, and it takes days rather than minutes.

Two-factor authentication protects your accounts by requiring something you have. Losing that something locks you out as effectively as it locks anyone else out, which is the whole point and also the problem.

Safety

Store backup codes somewhere secure and offline. Anyone who has them can bypass your two-factor protection entirely, so a note in an unlocked email inbox defeats the purpose of having it.

Step by step

  1. Look for your backup codes first.Every service shows single-use recovery codes when you set up two-factor. Password manager, a printout, a safe. This is the fastest route back in by a wide margin.
  2. Try another device that is still signed in.An old phone, a tablet, a work computer. An already-authenticated session can usually change the two-factor settings without a fresh code.
  3. Check whether the codes are in a cloud-synced app.Several authenticator apps sync across devices. Installing it on a new phone and signing in may restore every code at once.
  4. Use an alternative second factor.Many accounts allow more than one — a security key, an SMS fallback, a trusted device prompt. Check what else was registered.
  5. Start account recovery if none of that works.Every major provider has a process. It is deliberately slow — days, sometimes weeks — because it is the route an attacker would also take.
  6. Prioritise your email account above all others.Email is the reset route for everything else. Locked out of email, you are locked out of most of your digital life. Recover it first.
  7. Once back in, set up properly this time.New backup codes, printed and stored offline. A second factor on a second device. A recovery email or phone that you control.
  8. Do this for your important accounts now.If you are reading this before it happens: ten minutes today saves days later. Email, banking, and anything holding payment details.

Tips

  • Print backup codes and put them with your passport. Offline, secure, and findable by you in a crisis.
  • A physical security key as a second factor is both more secure and easier to recover, because you can register two and keep one elsewhere.
  • Do not store two-factor codes in the same password manager as the password, unless that manager itself is well protected. It collapses two factors into one.

Common mistakes

  • Not saving the backup codes at setup — They are shown once. Without them, recovery goes from minutes to days and sometimes fails entirely.
  • Having only one second factor, on one device — One lost or broken phone locks you out of everything at once. Register two wherever the service allows it.

Questions people ask

How do I get into an account if I lost my authenticator?

Backup codes first, then a device still signed in, then any alternative second factor. Failing those, the provider's account recovery process — which is deliberately slow.

Where should I keep backup codes?

Printed and stored somewhere physically secure. Anyone with them can bypass your two-factor, so not in an unprotected note or inbox.

Written and maintained by the GuideHQ editorial team. More in Technology.