Skip to content
Security

Locked out of your authenticator app

Losing the phone that holds your authenticator app does not mean losing the accounts behind it — but the way back depends entirely on what you set up before it happened.

Security2 min read

sim chip — illustration for “Locked out of your authenticator app”
Photo: Xerox ColorQube 8570 - Main controller - Smart Card-0420 — Raimond Spekking, CC BY-SA 4.0 (Wikimedia Commons)
On this page
  1. Try the other factors first
  2. Clean up the account before you lock yourself out again
  3. When nothing else is left

Losing the phone that holds your authenticator app does not mean losing the accounts behind it — but the way back depends entirely on what you set up before it happened. The fastest routes use something you still have; the slowest one puts you in an identity review that can run for weeks.

Try the other factors first

Start with a backup code. Every service that offers app-based two-factor authentication also issues a list of one-time codes when you switch it on, and any unused code still works after the phone is gone. Each one can be used once, so spend them carefully and generate a fresh list as soon as you are back in.

If there are no codes, look for a second factor that is not on the lost device: a hardware security key, a trusted device that is still signed in, a backup phone number, or a passkey stored in a password manager or in an account you can still open. At the sign-in screen this usually hides behind a link such as "try another way" or "having trouble".

Some authenticator apps also back up their seeds to a cloud account. If you enabled that, installing the app on a new phone and signing in restores the codes in one step. If you did not, the seeds were only ever on the old device and no amount of support will recover them.

Clean up the account before you lock yourself out again

Once you are in, go to the security settings and remove the authenticator entry for the phone you no longer have, then register the new one and verify it. Do the removal and the replacement in the same session: taking every method off an account and leaving it bare is what triggers the long mandatory waiting periods on several large services.

If the account belongs to an employer or a school, this is not your job at all. An administrator can clear the old registration so that the next sign-in asks you to enrol again, and that takes minutes rather than days.

When nothing else is left

With no codes, no second factor and no backup, what remains is the recovery form. It is an automated review that weighs how long your email address or phone number has been on the account, which devices have used it before and where the request is coming from, and it commonly takes several days. Filing it repeatedly makes things worse, not faster.

The lesson is cheap to apply afterwards: print the backup codes, keep a second factor on a device that is not the phone, and store both somewhere the phone cannot lock you out of.

More from Security

All stories
card uv — illustration for “How to spot unsafe sites”
Security

How to spot unsafe sites

It is possible to enjoy online casino games while remaining safe. This guide lays out easy, straightforward steps anyone can take to keep themselves safe.