Guide
Prevent getting locked out
You can still sign in, which means almost everything that makes recovery possible can still be set up — though some changes carry a trust delay, so this is not a job to leave until the day you need it. This is the only part of the lockout problem that is fully under your control, and it takes about ten minutes per account.
The one idea that matters most
A single passkey, a single phone, or a single saved code is a single point of failure. Add a second, independent way in — on different hardware, stored in a different place — and a lost device becomes an inconvenience instead of a disaster.
Add a second way in
- Add recovery contacts and details. Apple allows up to five recovery contacts, who can issue a recovery code during account recovery. Google lets you add recovery contacts, a recovery phone number and a recovery email address. Google warns not to use a Google Voice number as a recovery phone number, because it can lock you out. On Microsoft accounts, adding a phone number is not offered for every account; a recovery email, an authenticator app or a passkey may be the available options.
- Add a second passkey on different hardware. A passkey on a second device, or on a hardware security key, is the main insurance against losing one phone. Apple, Google and Microsoft all support more than one passkey. Adding a passkey does not remove your existing sign-in or recovery methods.
- Save the backup codes the account offers. Google, Microsoft, Bitwarden and 1Password all issue backup or recovery codes for a lost second factor. Print or download them, and remember that generating a new set usually invalidates the old one. A Microsoft recovery code cannot be retrieved later if you did not save it.
- Set up password-manager recovery deliberately. A 1Password recovery code, an Emergency Kit, a family organiser or administrator, and Bitwarden emergency access or organisation recovery are different routes with different prerequisites. At least two people should be able to recover a shared account.
- Review the devices and sessions on the account. Remove anything you do not recognise. This both improves security and makes it obvious later if something has changed.
Store codes where they will survive
The failure mode is simple: a recovery code stored only inside the thing it recovers cannot help you. Apple explicitly says not to store a recovery key in the Apple Passwords app, iCloud Photos, Notes or iCloud Drive, and recommends a printed copy kept in more than one place. 1Password recommends writing the account password on at least one printed Emergency Kit copy and recording the two-factor setup secret with it. The test is not secrecy alone — it is that the code survives the loss of the device and the account it belongs to.
| Recovery method | What it depends on | Independent? |
|---|---|---|
| Backup codes printed and kept somewhere else | Paper you can find after a house move or a lost bag | Yes, if it is not the only copy and is not left inside the account. |
| Backup codes saved as a note in the same password manager | The password-manager account you may lose access to | No. If the vault is the thing locked, the codes are locked with it. |
| Recovery key stored in the same provider's notes, photos or cloud drive | The account the key is meant to recover | No. Apple says explicitly not to store the key in that ecosystem. |
| A second passkey synced through the same manager and account | The same provider cloud and account | Partly. It survives a lost phone, but not losing the account itself. |
| A passkey on a hardware security key kept separately | The key, wherever it is physically kept | Yes, provided it is stored apart from the device it backs up. |
| An Apple or Google recovery contact | Another reachable person who agreed in advance | Yes, if the contact is reachable and still has their own access. |
A simple test for any method you set up: name the single event that would destroy it, then check that the event does not also destroy the thing it protects. Two methods that both depend on the same phone or the same account are one method, not two.
Expect a trust delay
Security changes often take effect slowly, on purpose. Plan for this on a day when you do not need the account immediately.
| Provider | What the provider documents |
|---|---|
| Adding or changing a recovery phone number can take up to 7 days to take effect. A recovery contact request lasts 7 days, then a further 7 days before the contact can be used. A newly added security key can take up to 7 days before it is available at sign-in, unless another trusted method speeds it up. | |
| Microsoft | If you remove all security information, Microsoft puts the account into a restricted state for 30 days. More broadly, with two-step verification on, Microsoft documents that losing your contact method can leave you unable to regain access for 30 days. |
| Apple | Setting up a recovery key turns off Apple's standard account recovery, so it is a strong protection with a strong failure mode. Two-factor authentication cannot be removed from an account created with it. |
| 1Password | Treat a recovery code as a setup step, not an instant escape hatch: it only works while you are signed out and have not been active recently, so set it up and store it now rather than when you are locked out. Wait at least one hour after creating one before you can rely on it. |
| Bitwarden | Using the two-step recovery code disconnects all two-step login methods, and a new code is generated afterwards. Emergency access requires a premium account, an invitation valid for five days, and a wait time of at least one day. |
Three things to avoid
Do not test recovery by signing out
Do not sign out of your only working session, and do not delete your only passkey, in order to check that another route works. If it does not, you have turned a temporary problem into a real lockout. Add and confirm the second route while signed in instead.
Do not set an Apple recovery key casually
A recovery key is 28 characters, and setting it up switches off Apple's standard account recovery. If you lose it, Apple states the account is locked out permanently and cannot supply the key. Only set one up with a printed copy stored in more than one place.
Do not store a recovery code in the vault it protects
Keep recovery codes and recovery keys out of the password manager, mailbox or cloud drive that they are meant to recover. A printed or offline copy is what survives an account lockout.
A short checklist
- Two or more sign-in methods, on different hardware.
- A current recovery email and phone number, both reachable.
- A recovery contact, where the provider supports one.
- Backup codes saved offline, and you know where they are.
- A password-manager recovery route set up, if you use one.
- Unknown devices and sessions removed.
- A written note of which method lives where, kept with the codes.
The interactive guide can turn this into a plan for your specific provider and concern.
Build a plan for your account
The prevention side of the step-by-step guide asks what you want to be prepared for and which service is involved, then gives a short, provider-specific plan. It never asks for a password, a code or a key.
Official sources
- Apple: Set up a recovery contact for your Apple Account
- Apple: Set up a recovery key for your Apple Account
- Apple: About trusted phone numbers and trusted devices
- Apple: Two-factor authentication for Apple Account
- Google: Set up recovery options
- Google: Use a security key for 2-Step Verification
- Google: Sign in with a passkey instead of a password
- Microsoft: Create and save a passkey
- Microsoft: How to use two-step verification with your Microsoft account
- Microsoft: Removing a sign-in verification method
- Microsoft: How to get a Microsoft account recovery code
- 1Password — Get to know your Emergency Kit
- 1Password — Generate and use recovery codes
- Bitwarden: Recovery code for two-step login
- Bitwarden: About emergency access
Passkey Lifeboat is independent and not affiliated with these providers. These pages were last checked on 16–17 September 2026; provider instructions can change, so the provider's own page is always the final authority.