Recovery codes for people locked out

Plan requirement

Subscription Any plan
Access Admin

The way back in when the phone is gone. They have to be generated in advance, because the moment you need them is the moment you cannot sign in.

How they work

  1. Each person generates their codes when enrolling in two-factor.
  2. They store them somewhere safe and separate.
  3. A code is used once to sign in without the authenticator.
  4. They generate a new set when the codes run low.

Generate them at enrolment

Not later. Somebody who has lost their phone cannot sign in to generate codes, which is exactly the situation the codes exist for.

Make it part of the enrolment instruction rather than a follow-up.

Not on the same device

Codes stored on the phone with the authenticator are useless when the phone is lost. A password manager on another device, or printed and kept securely, both work.

They are as good as the password plus the phone

Anybody holding a code can sign in. They deserve the same care as a password, which means not in a shared document and not in a chat message.

Have an admin route as well

People will lose both. An admin can reset somebody's two-factor enrolment, and that needs a verification step: confirm who is asking, ideally by voice or in person.

A reset granted on the strength of an email is a hole in the control you just spent effort putting in.

Write down the procedure

Who to contact, how they verify you, how long it takes. Three lines, kept where people can reach them without signing in to Zendesk.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.