Losing access to an authenticator app: existing authentication factors
Losing an authenticator can lock you out of accounts that depend on it. Inventory the factors protecting the account before losing access to an authenticator app; keep one independent method available while losing access to an authenticator app is in progress.
What can break first with losing access to an authenticator app
You may be unable to generate required one-time codes. Once the loss of access to your authenticator app is visible, test a signed-out login afterward. Make the first access risk of losing access to an authenticator app observable: test sign-in before the change and repeat it after the old factor is altered.
Recovery methods to prove before losing access to an authenticator app
Before finalising the authenticator-loss recovery process, try a signed-out or second-device recovery check. Store recovery material outside the browser.
Losing access to an authenticator app: backup factors and trusted devices
Billing may continue even while you are locked out. Test the fallback from another device. Store backup codes or recovery material away from the primary device before losing access to an authenticator app; confirm a trusted device still appears where you expect it.
Review active sessions before losing access to an authenticator app
Other people typically see no public change. Keep one known-good sign-in route alive while changing the authenticator-loss recovery process. Keep one independent recovery route working. Once the loss of access to your authenticator app is visible, remove only credentials you no longer trust.
Test account recovery after losing access to an authenticator app
Store backup codes securely. Enroll a second authenticator/security key where supported.
Recover the account without rebuilding dependence on one device
Start with recovery methods that were created before the loss: backup codes, a second authenticator, passkeys, trusted devices or provider recovery. Work from a device and network you trust, and avoid removing a remaining good factor until the account is stable again. After access is restored, review the factor list, replace obsolete recovery material and perform one signed-out login test. Recovery is complete only when both normal sign-in and a fallback route work.
Related consequence reports for “If you lose access to your authenticator app: what to do next”
- What happens if you lose access to your authenticator app?Security & 2FA
- What happens if you lose the phone that has your Google passkeys?Security & 2FA
- What happens if your phone is lost with WhatsApp logged in?Security & 2FA
- What happens if you lose access to your WhatsApp passkey device?Security & 2FA
- What happens if you sign out of Office remotely?Security & 2FA
- What happens if you disable two-factor authentication?Security & 2FA
Continue in this topic
Find more distinct decisions and source-backed consequence reports in the Security & 2FA topic hub.
Official sources for “If you lose access to your authenticator app: what to do next”
- NIST — Digital Identity Guidelines: AuthenticationOfficial source ↗
- FTC — Use two-factor authenticationOfficial source ↗
- Google — PasskeysOfficial source ↗
- FTC — Before you upgrade your phoneOfficial source ↗
- WhatsApp Help — Account deactivationOfficial source ↗
- WhatsApp Help — Change phonesOfficial source ↗
- WhatsApp Help — PasskeysOfficial source ↗
- Microsoft Support — Sign out of OfficeOfficial source ↗