PlaybooksMFA device lost or broken
Accessserious20 minutes to prepare

MFA device lost or broken

The phone or security key used to approve critical logins is unavailable, damaged, or stolen.

01DetectConfirm the signal
02ContainStop more damage
03RecoverRestore control
04VerifyProve it works

Your preparation

0 of 0 safeguards ready
0%
Incident worksheet

Make the next decision with evidence

Recover through pre-established factors, remove the lost authenticator, and avoid turning one missing device into permanent account loss.

EvidenceDecisionActionProof

Capture before evidence disappears

  • Record the device, accounts, authenticator type, SIM status, passkeys, push sessions, recovery factors, last location, and last successful use.
  • Preserve identity sign-ins, MFA prompts, factor changes, recovery attempts, support cases, device-management events, and carrier changes.
  • Identify accounts where the lost device is the only factor, a recovery email, a trusted session, or a password-manager key.

Decisions that change the response

QuestionAct whenAction
Remote lock or wipe?The device is lost and online; evidence and retrieval likelihood are considered.Lock it, revoke account sessions, then wipe when data risk justifies it.
Use provider recovery?No enrolled backup factor or trusted security key remains.Follow the official route from a known device; reject anyone offering an MFA bypass.

Proof that recovery worked

  • The lost device and its SIM cannot approve prompts, recover accounts, or use active sessions.
  • Each critical account has two tested, independent factors and fresh recovery material.
  • New-factor enrollment alerts and sign-in logs show only the recovery operator.

Controls to put in place

  • Enroll two phishing-resistant hardware or platform factors for critical accounts.
  • Store recovery codes encrypted and offline from the primary phone and password manager session.
  • Review trusted devices, factors, phone numbers, and recovery email quarterly.
Tabletop drill

Turn off the primary authenticator. Recover one critical account with a backup key, remove the old factor, issue new recovery codes, and prove a second operator can follow the record.

Escalate when

Contact the carrier for SIM risk and the provider for official recovery. Treat unexplained factor changes or prompts as an identity compromise, not a lost-device exercise.

What this means

Critical accounts may be safe but inaccessible. If the device was stolen, active sessions, notifications, local files, and SMS-based recovery may also be exposed.

Warning signs

  • The only authenticator phone or security key is missing.
  • Login prompts arrive that nobody initiated.
  • The phone number was transferred or stopped working.
  • Backup codes are unavailable or fail.

Recover now

First 15 minutes

  1. Lock or erase the missing device remotely. Preserve its serial number and last known location.
  2. Use a spare security key or recovery code. Start with email, password manager, domain, cloud, and payments.
  3. Call the mobile carrier if a SIM is involved. Add a port lock and replace the SIM.
  4. Do not disable MFA broadly. Recover one account at a time through its official flow.

Today

  1. Remove the missing authenticator from every recovered account.
  2. Register two independent phishing-resistant factors.
  3. Review recent sessions and security changes for unexpected activity.
  4. Replace recovery codes and store them outside the primary device.

Verify recovery

  • The missing device can no longer approve logins.
  • Two independent factors work on every critical account.
  • No unknown sessions or recovery methods remain.
  • A second authorized person can complete recovery.

Prepare now

Access

  • Critical accounts have at least two security keys or passkeys.
  • SMS is not the only recovery factor for privileged accounts.

Backups and evidence

  • Fresh recovery codes are stored offline and can be read.
  • Device serial numbers and remote-lock instructions are recorded.

Contacts and ownership

  • Carrier and provider recovery contacts are available without the phone.

Practice

  • One factor has been removed and replaced in a safe test.

Common mistakes

  • Keeping both security keys together. One lost bag removes both.
  • Using the lost phone to store its own recovery codes.
  • Accepting unexpected MFA prompts. This can approve an attack.

Sources

Last reviewed July 19, 2026Guidance changes. Confirm provider-specific actions in the linked official sources.