If you are locked out, missing codes or moving to a new phone, do not reset two-factor authentication straight away. First check which sign-in method your account uses: text message, authentication app, email, security key or backup codes. Also check whether your phone number, device clock or recovery details have changed.
Two factor authentication help: find the failed step
A one-time passcode is a short code that expires, often within 30 to 60 seconds for an authentication app. Identify whether the account wants an SMS, app code, email code, passkey or recovery code, because these are separate methods.
Check the code type and account
Check the email address or username shown on the sign-in page before entering anything. An authenticator app can hold several entries with near-identical names, especially for personal and work accounts.
Fix time, signal and app issues
Set your phone to automatic date, time and time zone, then reopen the authentication app. A clock that is even a minute or two wrong can make its rotating code fail.
Stop after one or two rejected codes. Repeated retries may create a temporary block lasting between 15 and 30 minutes. Use a verified backup method instead of requesting more codes.
Recover access with the method still available
The safest recovery path is the strongest method you still control: a recovery code, signed-in device, passkey, authentication app, verified email, then the provider's identity check.
Choose your route by what you lost
- Lost phone, still signed in elsewhere: add a new method from that device, then remove the lost phone.
- Lost number but have recovery codes: use one recovery code, add a new number and create fresh codes.
- Lost authenticator app only: use a passkey, trusted device or official recovery page.
- Lost email access: secure the email account first, because it is often the master key for password resets.
A genuine support team will not ask you to read out a current security code, a recovery code or your full password. A text claiming a savings account is at risk, followed by a caller requesting the code sent to your phone, is a common scam.
Use a simple recovery order when lost phone access affects more than one method. If you still have a trusted device, sign in there first, remove the old phone and add the new number after changing your phone number. If the authenticator is missing but backup codes remain, use one code only and generate replacement backup codes once signed in. If the old phone, app and codes are all unavailable, secure the email account and begin the provider’s official account recovery process; do not rely on unofficial callers or paid recovery services.
Before assuming an app code is wrong, check device clock sync and confirm that the selected account entry matches the service you are trying to access. This approach makes two-factor authentication recovery less likely to create a permanent lockout.
Move 2FA before wiping an old phone
Keep the old phone switched on until you have successfully signed in on the new device and tested a backup method.
Transfer accounts and test each one
On the old phone, open each important service and add the new authentication method. Test a new code or passkey on the new phone before removing the old entry.
Find security settings and understand passkeys
A passkey is a sign-in key held by your device or password manager, usually unlocked with your fingerprint, face or screen PIN. It can resist phishing better than a typed code because it checks the real website before signing in.
Safe phone-change order
1. Keep old phone
2. Add new method
3. Test sign-in
4. Save backup codes
5. Remove old phone
To turn on 2FA, start from the account’s official security area rather than a link in an email or message. In a Google Account, open Security and choose 2-Step Verification; in a Microsoft account, go to Security, then Advanced security options, and select Two-step verification. For Apple, use Settings > your name > Sign-In & Security on an iPhone. On Facebook, open Settings & privacy > Settings > Accounts Centre > Password and security > Two-factor authentication.
In X, use Settings and privacy > Security and account access > Security > Two-factor authentication. Menu names can change, so check the provider’s official help page if an option is not visible.
Choose safer 2FA for online savings accounts
For most people in England, an authentication app plus stored recovery codes is the best balance of safety and ease. Passkeys and physical security keys give stronger phishing protection, while SMS should not be the only route into a Cash ISA, Premium Bonds or other online savings account.
| Method | Phishing resistance | Needs phone signal | Main risk |
|---|
| Passkey | High | No | No backup device |
| Physical key | High | No | Lost key |
| Authenticator app | Medium | No | Phone migration |
| SMS or email | Low | Usually | SIM swap or inbox theft |
A physical security key is a small USB or NFC device used as a second sign-in proof. It suits people protecting large savings balances, business email or accounts targeted by repeated phishing attempts.
📦
Find it on Amazon
A USB or NFC security key can add a separate sign-in proof for accounts that support it. Keep a spare key in a different secure place.
- Works without mobile signal or an SMS code
- Helps block fake websites that ask for temporary codes
- Provides a backup when a phone is lost or replaced
Search Amazon →
Keep two independent backup routes
Keep recovery codes away from the phone and add a second method, such as a passkey or security key. Do not rely on SMS alone because a SIM swap can move your number to a criminal's SIM card.
Choose the method based on both risk and recovery options. Authentication app codes work without mobile signal, but require a careful phone transfer; a passkey sign-in is usually convenient on a personal device and checks the genuine site before approval. A security key offers similar phishing protection and is useful for high-value accounts, although keeping a spare is sensible. Approval prompts are quick but should never be accepted unexpectedly, as repeated prompts can be used to pressure a user.
An SMS verification code depends on control of the phone number and can be exposed by SIM swap, while email codes are only as secure as the email account. For online savings account security, keep at least two independent methods.
FAQs
Why is my two-factor code not working?
It is often the wrong code type, account or device time. Stop after one or two failures and use a backup route.
Can I recover 2FA without my old phone?
Yes, if you have a recovery code, passkey, trusted signed-in device or verified email. Otherwise, use the provider's identity process.
Does changing my phone transfer my authenticator?
No, not for every account. Transfer or re-register each service and test the new device before wiping the old one.
Is SMS verification safe enough for savings?
SMS is better than no second step, but weaker than an app, passkey or physical key. Keep a backup method.
Can support ask for my 2FA code?
No legitimate provider needs your current code or recovery codes by phone, text or email.
How do I turn on 2FA on an iPhone?
Open Settings, tap your name, then Sign-In & Security. Apple may ask you to confirm a trusted phone number.
What is the difference between 2FA and MFA?
2FA uses exactly two proofs of identity, while MFA uses two or more.
This advice does not replace a provider's recovery process or the identity checks required by a financial firm. If you suspect fraud, a SIM swap, a stolen device or unauthorised access, secure your main email first, contact the provider only through official channels and review active sessions.
What to do next to avoid another lockout
Set up an authentication app or passkey, save recovery codes separately and add one backup method. Check it immediately while you are still signed in.
Related sources
These articles can help you explore the topic in more depth: