How to Set Up Two-Factor Authentication Without Getting Locked Out

Information current as of 09/11/2026.

Before enabling or changing two-factor authentication, review the methods your provider supports and add at least one backup authenticator or recovery method. Generate recovery codes, store them securely away from the sign-in device, and test the new authenticator and at least one recovery path while you are still signed in. Replace, reset, or remove the old device only after those tests succeed.

Use more than one way to authenticate

Start by checking the account’s supported options. When available, phishing-resistant methods such as passkeys or security keys are preferred; otherwise, use a supported authenticator app or another provider-approved method. Maintain at least two valid authenticators, and add the backup method before removing or replacing the primary device. Availability varies by provider, country, account type, and security level.

Store recovery codes separately from your sign-in device

Generate recovery codes during setup if the provider offers them. Treat them like sensitive credentials: do not share them or enter them anywhere except the provider’s genuine sign-in flow. Store them offline or in another separately secured location rather than in an unprotected notes app, screenshot folder, or on the device used to sign in. Some providers invalidate earlier codes when a new set is generated, so follow the provider’s instructions and replace exposed codes.

Test every backup path before replacing the old device

While the account is still accessible, sign out or use a private browser window to test the new authenticator and at least one recovery option. Confirm that the recovery code, alternate authenticator, recovery contact, or other method works according to the provider’s process. Do not assume that authenticator backup and restoration will work across different device platforms. Only after successful testing should you wipe, reset, replace, or remove the old device.

If the device is lost or stolen

Use an available backup method to sign in, remove or suspend the lost authenticator, and enroll a replacement. If no alternate verification method is accessible, the provider may be unable to restore access immediately; replacing a lost authenticator can require additional identity verification or a longer recovery process. Watch for provider notifications after recovery activity so unauthorized attempts can be detected.

Sources