Your preparation
0 of 0 safeguards readyMake the next decision with evidence
Recover through pre-established factors, remove the lost authenticator, and avoid turning one missing device into permanent account loss.
Capture before evidence disappears
- Record the device, accounts, authenticator type, SIM status, passkeys, push sessions, recovery factors, last location, and last successful use.
- Preserve identity sign-ins, MFA prompts, factor changes, recovery attempts, support cases, device-management events, and carrier changes.
- Identify accounts where the lost device is the only factor, a recovery email, a trusted session, or a password-manager key.
Decisions that change the response
| Question | Act when | Action |
|---|---|---|
| Remote lock or wipe? | The device is lost and online; evidence and retrieval likelihood are considered. | Lock it, revoke account sessions, then wipe when data risk justifies it. |
| Use provider recovery? | No enrolled backup factor or trusted security key remains. | Follow the official route from a known device; reject anyone offering an MFA bypass. |
Proof that recovery worked
- The lost device and its SIM cannot approve prompts, recover accounts, or use active sessions.
- Each critical account has two tested, independent factors and fresh recovery material.
- New-factor enrollment alerts and sign-in logs show only the recovery operator.
Controls to put in place
- Enroll two phishing-resistant hardware or platform factors for critical accounts.
- Store recovery codes encrypted and offline from the primary phone and password manager session.
- Review trusted devices, factors, phone numbers, and recovery email quarterly.
Turn off the primary authenticator. Recover one critical account with a backup key, remove the old factor, issue new recovery codes, and prove a second operator can follow the record.
Contact the carrier for SIM risk and the provider for official recovery. Treat unexplained factor changes or prompts as an identity compromise, not a lost-device exercise.
What this means
Critical accounts may be safe but inaccessible. If the device was stolen, active sessions, notifications, local files, and SMS-based recovery may also be exposed.
Warning signs
- The only authenticator phone or security key is missing.
- Login prompts arrive that nobody initiated.
- The phone number was transferred or stopped working.
- Backup codes are unavailable or fail.
Recover now
First 15 minutes
- Lock or erase the missing device remotely. Preserve its serial number and last known location.
- Use a spare security key or recovery code. Start with email, password manager, domain, cloud, and payments.
- Call the mobile carrier if a SIM is involved. Add a port lock and replace the SIM.
- Do not disable MFA broadly. Recover one account at a time through its official flow.
Today
- Remove the missing authenticator from every recovered account.
- Register two independent phishing-resistant factors.
- Review recent sessions and security changes for unexpected activity.
- Replace recovery codes and store them outside the primary device.
Verify recovery
- The missing device can no longer approve logins.
- Two independent factors work on every critical account.
- No unknown sessions or recovery methods remain.
- A second authorized person can complete recovery.
Prepare now
Access
- Critical accounts have at least two security keys or passkeys.
- SMS is not the only recovery factor for privileged accounts.
Backups and evidence
- Fresh recovery codes are stored offline and can be read.
- Device serial numbers and remote-lock instructions are recorded.
Contacts and ownership
- Carrier and provider recovery contacts are available without the phone.
Practice
- One factor has been removed and replaced in a safe test.
Common mistakes
- Keeping both security keys together. One lost bag removes both.
- Using the lost phone to store its own recovery codes.
- Accepting unexpected MFA prompts. This can approve an attack.