- An administrator or user loses their security key.
- A user loses their phone and can't generate 2SV codes.
- A user doesnât enroll in 2SV by the end of the new user enrollment period.
- A newly created user can't sign in to their account to set up 2SV.
Important: Google is enforcing 2SV for administrator accounts. For details, go to About 2SV enforcement for admins.
Prepare for account recovery
- Administrators should have a spare security keyâAdministrators should enroll more than one security key for their administrator account and store it in a safe place.
- Save backup codes ahead of timeâAdministrators and users should generate and print backup codes in case theyâre needed in the future. Keep backup codes in a secure location.
- Generate codes for a userâIf a locked-out user doesn't have backup codes, you can generate codes for them. See the instructions in User account on this page.
- Set up an additional administratorâIf an administrator canât sign in to their administrator account, another administrator can generate backup codes for them.
- If security keys are required, set up a grace periodâWhen you set up enforcement for 2SV, set up a grace period. Users can enter an admin-generated backup code for 2SV during the grace period. If 2SV is enforced in Only security key mode, users cannot generate their own backup codes. For details, go to Deploy 2-Step Verification.
Use backup codes for account recovery
If you need to recover an account, use backup codes. Accounts are still protected by 2SV, and backup codes are easy to generate. If you move users into a configuration group or change their organizational unit and 2SV isnât required, their accounts are no longer protected by 2SV. For more details, go to Avoid account lockouts when 2-Step Verification is enforced.
Recover an account
Watch the video
Recover an account protected by 2-Step Verification
Recover a user account
You can only access 2SV settings for a user and complete these steps if 2SV is currently enforced for your organization or the user turned on 2SV for their account.
-
Sign in with an administrator account to the Google Admin console.
If you arenât using an administrator account, you canât access the Admin console.
- Go to Menu
Directory > Users.
- Click the user you want in the list.
You see summary information about that user. If you need help, see Find a user account. - Click Security.
- Click 2-step verification.
- Click Get Backup Verification Codes.
- Copy one of the verification codes.
- Send the backup code to the user in an IM or text message.
The user can sign in to their account using a password and the backup code.
- Ask another admin at your company to generate backup codes, as described earlier in recovering a user account.
- If another administrator isnât available, follow the instructions to reset your administrator password.
About using a secondary username for account recovery
In some cases, you can use a secondary username to recover your account. This practice is discouraged because itâs not secure. If the secondary username isnât covered by 2SV, it can be compromisedâand so can your administrator account.
If your company has 3 or more super administrators or more than 500 users, you canât use a secondary username for account recovery (itâs disabled).