Print them, store them somewhere physical the business controls, and record which accounts they belong to. A phone can be lost, stolen, or wiped at any time.

The moment they are generated

When two-factor is switched on, most services offer a set of one-time recovery codes and suggest saving them.

That moment is the worst possible time to think carefully about it: the person is halfway through a setup, wants to finish, and has no reason to imagine losing the phone in front of them.

So the codes are dismissed, screenshotted onto the same phone, or saved into a file nobody can find later.

Which means the safeguard exists and is unavailable at the only moment it matters.

What actually happens

The second is the most common by far, and the most avoidable. Authenticator applications do not always move with a phone upgrade, and people discover this after the old device has been wiped and traded in.

Where to keep them

The decision, and the answer is more physical than people expect.

Printed, on paper, in a locked drawer or a safe at the business premises.

That sounds unsophisticated and it is correct, because the failure being planned for is the loss of a digital device, and a second digital copy shares that risk.

Do not store them on the same phone, which defeats the purpose entirely, and do not email them to yourself, since the email account is frequently the one you are locked out of.

A password manager is a reasonable second location, provided you can still reach the manager without the lost device.

The test is simple: could you reach these with no phone at all.

Label them properly

The step that makes them usable and is skipped every time.

A page of sixteen-character strings with nothing else on it is close to useless a year later.

Write the service, the account name, the date generated, and whose account it is on the same sheet.

Keep one sheet per account rather than a combined list, since codes get used and crossed off and a shared sheet becomes ambiguous.

Note that each code works once, so cross one off as you use it, and regenerate the set when you are down to the last two.

A worked example

A business owner upgraded his phone, traded the old one in, and discovered the following week that his authenticator had not transferred.

He was locked out of the email account that controlled the domain, the hosting, and the accounting software.

The recovery codes had been screenshotted onto the phone that was now gone.

Recovery through the provider took nine days and required documents proving the business, during which he could not access his own email.

Afterwards he printed codes for every account, put them in the office safe, and added moving the authenticator to a written checklist for phone upgrades.

The nine days had been entirely avoidable by a printout.

Whose codes, and who can reach them

The business continuity question, which is separate from the personal one.

Codes held only by one person are useless when that person is unavailable, which is the situation they are most needed in.

For accounts the business depends on, somebody other than the day-to-day user should be able to reach the codes.

That is a trust decision and it belongs alongside who holds keys to the premises, which most businesses have already settled.

Where that is uncomfortable, a sealed envelope in a safe, opened only in a defined situation, is a reasonable middle position.

The alternative is a business unable to reach its own accounts because one person is on holiday.

The other routes back in

Since recovery codes are one option among several and the others need checking too.

A recovery email address, which must be one you still control and which should not be the account itself.

A recovery phone number, which needs updating when numbers change and frequently is not.

A second authenticated device, which several services allow and almost nobody sets up.

Adding a second device at setup time is the single best safeguard, since it removes the single point of failure entirely.

Check all three annually, since a recovery address at a former employee's mailbox is a real and common problem.

Add it to the phone upgrade routine

Because that is where most of these incidents originate.

Before wiping or trading an old device, move the authenticator across and confirm the new one produces working codes.

Do that before disposing of the old phone rather than afterwards, which is the entire lesson.

Write it on whatever checklist the business uses for equipment, since it is the kind of thing nobody remembers at the moment it matters.

The same applies to somebody leaving: transfer or regenerate anything on their device before the last day.

Regenerate after anybody leaves

The occasion nobody connects to this and should.

Somebody who has left may have seen or copied recovery codes for accounts they used, and those codes keep working indefinitely.

Removing their account and changing the password does nothing about a code they wrote down eighteen months ago.

Regenerate the codes for any account they had access to, which invalidates every previous set, and print the new ones.

Add it to whatever you already do when somebody leaves, alongside keys, email, and access, since it is the item on that list that survives everything else.

The counter-case

Paper has its own risks.

Codes in a drawer can be found by anybody with access to the premises, which for some businesses is a worse exposure than the lockout they prevent.

A locked drawer or safe is the answer rather than a desk, and for accounts holding sensitive data that distinction matters.

There is also a version of this that becomes elaborate, with sealed envelopes and procedures nobody follows, for a business with two people and three accounts.

Print them, label them, lock them, add a second device where you can, and check the recovery addresses once a year.

What to do

  1. Print the codes, one sheet per account.
  2. Label with service, account, date, and person.
  3. Lock them somewhere physical on the premises.
  4. Never store them on the same phone.
  5. Add a second authenticated device.
  6. Check recovery addresses annually.
  7. Move the authenticator before wiping a phone.

Step five removes the problem rather than preparing for it, and it takes two minutes at the moment two-factor is being set up.

The wider version of this problem is covered in losing a phone with everything on it.


Frequently asked questions

Why do recovery codes get lost?

They are generated mid-setup, when nobody is thinking about losing the phone in front of them, so they are dismissed, screenshotted onto the same phone, or saved somewhere unfindable.

What is the most common cause of a lockout?

A phone upgrade. Authenticator applications do not always move with a new device, and people find out after the old one has been wiped and traded in.

Where should the codes live?

Printed, on paper, in a locked drawer or safe. The failure being planned for is losing a digital device, so a second digital copy shares that risk.

How should they be labelled?

Service, account name, date generated, and whose account it is, one sheet per account. A page of unlabelled strings is useless a year later.

Who else should be able to reach them?

For accounts the business depends on, somebody other than the daily user, since codes held by one person are useless when that person is unavailable.

What is the best safeguard?

Adding a second authenticated device at setup, which several services allow and almost nobody does. It removes the single point of failure entirely.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Codes screenshotted onto the phone they protect?

Print them and lock them somewhere physical. The failure you are planning for is losing that phone.

Start a Conversation