Multifactor authentication protects an account by requiring more than a password. That extra factor may be a passkey, security key, authenticator app, trusted device, push approval, text message, or another provider-supported method. It also creates a continuity question: what happens when the phone is lost, stolen, broken, discharged, without service, or left behind during an evacuation?
The safest answer is prepared before the phone disappears. Register legitimate alternatives, secure backup codes, verify recovery details, and understand the provider’s process while normal access still works. Do not weaken MFA or reuse passwords merely to make an emergency login easier.

First decide whether the phone is unavailable or untrusted
These are different incidents:
- Unavailable but controlled: the phone is at home, out of charge, offline, damaged, or temporarily inaccessible.
- Lost: the location is unknown, but theft is not confirmed.
- Stolen or possibly accessed: another person may possess the device, SIM, notifications, or active sessions.
- Compromised: the device or account shows unexpected prompts, sessions, forwarding, settings, messages, or transactions.
- Managed: an employer or school owns the device or controls the account.
For a simple battery or connectivity problem, a registered offline factor may be enough. For theft or compromise, treat the device and its sessions as potentially exposed and involve the carrier, provider, organization, or financial institution promptly.
Use fallback methods in a safe order
The exact order belongs to the provider. Common legitimate options include:
- a passkey or authenticator on another already registered trusted device;
- a separate registered security key;
- a provider-issued backup code;
- a second verified phone number or provider-supported voice method;
- a recovery contact or family recovery feature;
- an organizational administrator for work or school;
- the provider’s formal identity and account-recovery process.
Start through the known app or official site, not a link sent after the loss. A search result, sponsored advertisement, social-media account, or incoming caller may impersonate support. The FBI has warned that even federal reporting sites can be spoofed; manually entering a known official address reduces that risk.
Do not repeatedly guess codes or passwords. Repeated attempts can trigger additional controls, obscure the real problem, or increase urgency. Read the message, record the provider’s stated next step, and use the documented fallback.
If the phone may be stolen
From a known-clean device and verified channel:
- Check personal safety; do not confront a suspected thief.
- Use the platform’s official lost-device feature if it was enabled and appropriate.
- Contact the carrier to report possible device or SIM loss and ask about the account’s official protection process.
- Secure the primary email and password manager because they may reset other accounts.
- Review recent sessions, recovery methods, forwarding, and alerts.
- Revoke the missing device or session after considering platform, employer, insurer, and law-enforcement instructions.
- Replace exposed MFA methods and issue new backup codes once legitimate access is restored.
- Check financial, payment, cloud, communication, work, health, and social accounts for unauthorized activity.
- Record times, actions, provider cases, and any suspicious transactions.
Remote lock, location, and erase actions may require the device to reconnect. Erasure can affect later tracking, evidence, or recovery. Follow the current official platform instructions rather than assuming one action fits every incident.
If a blackout is the only problem
An authenticator app may generate codes without cellular service, but the login service and device still need whatever connectivity and time synchronization their design requires. A text message may be delayed when networks are congested. A push request requires connectivity. A physical security key may work locally with a compatible powered device, but it does not guarantee that the account service is reachable.
Prepare by:
- keeping the primary device charged safely;
- storing compatible charging cables and a modest power bank;
- registering an independent factor where supported;
- printing or securely storing provider backup codes;
- keeping essential provider and organization contacts on paper;
- downloading necessary non-secret information for offline use;
- deciding which tasks can wait until service returns.
Do not exhaust limited power repeatedly refreshing an unavailable service. Use the power outage communication plan and the power outage hub for household priorities.
Prepare backup codes correctly
Backup codes are high-value credentials. Provider behavior varies, but codes may be single-use, replaceable, printable, or invalidated when a new set is created. Google’s official guidance, for example, says its backup codes become inactive after use and that generating a new set invalidates the old set. Do not generalize those exact rules to every service.
For each provider that offers codes:
- generate them only while signed in through the official service;
- confirm what invalidates or replaces them;
- store them away from the protected device;
- do not photograph them into the same cloud account they recover;
- do not label an exposed copy with more identifying information than needed;
- limit access and keep a second controlled path only when justified;
- replace the set after use, exposure, or a provider-directed security reset;
- securely destroy superseded paper or files.
Never type a backup code into a form reached through an unsolicited message. A provider may ask for one during its own login flow, but support should not need you to read the code to a caller.
Use more than one device only with control
Registering a second authenticator, passkey, or security key can improve continuity, but each new factor is also an access path. Keep an inventory:
| Factor | Account | Custodian | Secure location category | Last checked | Revocation trigger |
|---|---|---|---|---|---|
| primary phone app | account holder | carried device | date | loss or replacement | |
| secondary key | email and vault | named adult | controlled off-device location | date | loss, damage, household change |
| backup codes | provider | named adult | sealed controlled record | date | use, exposure, new set |
| recovery contact | device account | trusted person | provider record | date | relationship or contact change |
Do not record the code or secret in this inventory. The offline credentials guide explains how to separate the map from protected recovery material.
Avoid five dangerous shortcuts
- Turning MFA off permanently because one recovery was difficult.
- Adding a shared phone number without considering takeover, privacy, or household changes.
- Approving repeated push requests to make notifications stop.
- Sending codes or keys to someone who claims they found the phone.
- Installing a remote-support tool at the direction of an incoming call or message.
After recovery, change any password that may have been exposed, sign out unknown sessions, verify recovery details, review account activity, and strengthen the factor setup. FTC guidance recommends those controls after regaining a hacked account.
Run a low-risk quarterly check
Without signing out or disabling the working factor:
- list priority accounts and enrolled factor types;
- confirm backup-code storage without exposing the codes;
- verify recovery phone, email, and trusted contacts;
- check that alternate hardware is present, compatible, and not damaged;
- remove obsolete devices and contacts through official settings;
- update the response card for a lost phone;
- record the review date and owner.
Use the password recovery planning checklist for account dependencies and the digital continuity hub for backup, power, and data recovery.
Sources reviewed
- Federal Trade Commission: Use Two-Factor Authentication; How to Protect Your Phone From Hackers
- NIST: How Do I Create a Good Password?
- Google Account Help: Sign In With Backup Codes
- Apple Support: Set Up an Account Recovery Contact
Sources reviewed July 14, 2026. Provider features and recovery rules change. Follow the current official instructions for the exact account, factor, device, and organization.