How to set up MFA backup methods so you don't get locked out
Losing a primary mobile device often locks people out of their accounts because they have no configured backup authentication method or bypass option. Without a pre-established alternative, individuals are forced to file tedious IT support tickets just to re-establish access on a new device.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Contacting an administrator to reset the account or enable a temporary bypass
- 2Using a physical hardware token like a Yubikey or enrolling a secondary device
- 3backing up authenticator apps manually using separate personal accounts
- 4resetting accounts and re-registering all MFA tokens through IT support tickets
In their words
Unedited, most upvoted first, each linked to the thread it came from.
“this. it’s a massive pain in the ass to go around filing support tickets everywhere in order to re establish MFA on new device MS authenticators.”source ↗
“now they can't login, can't find Microsoft Authenticator, found it but it has no accounts in it...”source ↗
“But, I don't have my phone anymore. The cell shop took it and already resold it to someone in Pakistan.”source ↗
“I am trying to setup Duo Security on my PC at the office so that in the event I lose my phone or my phone is smashed what do I need to enable in the installation process to allow me to bypass the MFA/Passkey push?”source ↗
Where this came up
People with this problem also raised
- 2Fixing security token enrollment errors for non-technical users
- 2Why is step-up authentication forced and buggy?
- 2Can multiple Windows users open a KeePass database?
- 2How to migrate away from 1Password safely
- 2Why does accounting software force logins for every company file?
- 5Why am I getting DMARC and SPF errors when emails deliver fine?