Administration
Losing your second factor
A new phone, a wiped phone, a deleted app. A minute's work if you kept what needed keeping.
A second factor protects the account from someone getting in with a stolen password. It works so well that it also locks you out the day the phone is replaced, wiped or lost — and that day is rarely a calm one.
The three cases, and what differs between them
| What happened | Is there still an open session | Way out |
|---|---|---|
| New phone, old one to hand | Usually yes | Set the second factor up again from settings, calmly |
| Phone wiped or app deleted | Sometimes | The recovery codes, if they were kept |
| Phone lost or stolen | Possibly, and that is the urgent part | Close sessions and change the password first |
Important
The part that catches everyone out: **recovery codes are single use**. They are not an alternative password that always works — each one you use is spent and stops working, and they come as a handful, not an endless list. They are also shown **only once**, when the second factor is switched on. Whoever did not copy them then does not have them, and there is nowhere to look them up again.
Where the codes should live
Watch out
What almost nobody plans for: **the second factor is managed from each person's own settings, not from the admin ones**. A colleague, however senior an administrator, does not switch yours back on with a click. With no codes and no open session, getting back in goes through support and through proving who you really are — and that takes time, on exactly the day something had to be signed.
The five minutes that save the bad day
- 1
Switch the second factor on and copy the codes there and then
Not «later»: the screen does not come back.
- 2
Keep them somewhere that is not the phone
Password manager or paper.
- 3
Add the second factor in two places if you can
Many apps also allow it on a tablet or computer.
- 4
And when changing phone, migrate it before wiping the old one
The most repeated mistake, and the most avoidable.
Worth knowing
If you suspect the loss was not accidental, the order changes: close sessions and change the password first, then recover access at your own pace.
›Can I turn the second factor off «in the meantime»?
Only from inside. And if you can get in, better to fix it than switch it off.
›Can new codes be generated?
Yes, from settings, and it is worth it when few are left: the old ones stop working.
›What if the whole company shares one phone?
That is a different and bigger problem: one each.
A real case
The situation
Someone changes phone and wipes the old one before migrating the second-factor app.
What you do
- Uses one of the codes kept in the password manager and sets it up again
What you get
Access is back in a minute at the cost of one code, instead of raising a support case.
The situation
The second factor is lost and nobody can sign in.
What you do
- Recovers access with the administrator
What you get
The account comes back without switching security off.
The situation
The only administrator is the one who lost it.
What you do
- Keeps two administrators active
What you get
Somebody can always recover.
The situation
The second factor is switched off to get past it.
What you do
- Restores it on the new device
What you get
Security does not stay off.
The situation
It is lost along with the phone and an open session.
What you do
- Closes the sessions as well as recovering
What you get
The previous access is cut.
The situation
It happens often and is always fixed by hand.
What you do
- Documents the procedure
What you get
Recovery stops depending on whoever knows.
This article answers
- changed phone and cannot log in
- lost my verification codes
- what are recovery codes for
- regain access without my phone