Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What happens when backup codes are not saved…
Cyber Security

What happens when backup codes are not saved after enabling two-factor authentication?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Cyber Security

If backup codes are not saved, users can lock themselves out when they lose access to their phone, authenticator app, or security key. Recovery then becomes slower and may require manual account verification. A safe process stores the codes separately from the login credentials, such as in a secure note or other protected repository.

Why Unsaved Backup Codes Become an Account Recovery Problem

Backup codes are the fallback path when your primary second factor is unavailable, so failing to save them removes the safety net you were relying on. If the phone, authenticator app, or security key is lost, damaged, or reset, the account may no longer have a usable second factor to complete login, and recovery shifts from a normal sign-in flow to a manual identity-verification process.

The practical issue is not just inconvenience. Backup codes are usually designed as a last-resort recovery control, which means their absence increases dependency on help desk or account-owner intervention. In environments that treat authentication as part of access governance, the missing codes turn a self-service recovery path into an exception case that is slower, more error-prone, and more likely to be delayed by verification checks.

How Loss of the Fallback Changes the Login and Recovery Flow

When backup codes are unavailable, the user is forced to prove access through whatever alternate recovery steps the account provider allows. That may include email recovery, phone verification, documented support requests, or manual review by an administrator. In practice, the exact outcome depends on the account system, but the key effect is the same, the user cannot independently bypass the missing factor.

This matters because modern authentication is often built around layered recovery options. If the only second factor was tied to a single device and the backup codes were never saved, the account can become unrecoverable for the user until a trusted recovery process is completed. That is why the safest pattern is to treat backup codes as recovery material, not as an optional convenience.

  • Store backup codes separately from the primary login device.
  • Use a protected location that you can still access if your phone is lost.
  • Test that the recovery path works before you need it.
  • Replace or regenerate codes after major account changes, when the provider supports it.

What Good Recovery Hygiene Looks Like in Practice

Good practice is to assume the original second factor will eventually be unavailable. That means saving backup codes at the moment two-factor authentication is enabled, keeping them in a protected repository, and making sure the storage choice is independent of the device used for daily login. A secure note, password manager entry, or similarly protected store is typically better than a screenshot or paper left where others can find it.

This is also a governance issue for shared or managed accounts, because recovery must be supportable when the original enrolment owner is absent. For high-value accounts, teams should confirm who is allowed to recover access, what evidence is required, and whether the backup method survives device replacement and app reinstallation. Without that planning, a basic login problem can become an outage or an access dispute.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS Control 6 — Access Control ManagementBackup codes affect account recovery and access continuity.
Recommendation — Document and test recovery paths so lost factors do not block legitimate access.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlThe topic is about preserving authentication access when a factor is lost.
Recommendation — Maintain alternate recovery controls so authentication failures do not become account lockouts.
NIST SP 800-63Sec. 4 — General Identity Proofing and Authentication RequirementsBackup codes are part of authentication recovery after a factor becomes unavailable.
Recommendation — Bind recovery procedures to verified identity and test them before relying on them.
OWASP Non-Human Identity Top 10NHI-05 — Credential and Secret RotationSaved backup codes are recovery secrets that should be handled as protected authentication material.
Recommendation — Store recovery codes separately and rotate them when account recovery material changes.

Practitioner Guidance

What to verify: Confirm that the backup codes were generated, saved, and stored somewhere the user can reach after a device loss. If the codes only exist on the same phone, the fallback is not really a fallback.

Decision rule: If the account protects business-critical systems, treat unsaved backup codes as a recovery gap, not a minor setup oversight. The right response is to create a new recovery path now, before the original device is lost.

Common mistake: People often assume the authenticator app itself is the backup. It is not. The app is still a single point of failure if it is tied to one device and no separate recovery material was retained.

What good looks like: A user can lose the original phone and still regain access through a documented, tested, and independently stored recovery method without depending on guesswork or emergency escalation.

Practitioner takeaway: Two-factor authentication is only resilient when the recovery path is also resilient, so saving backup codes is part of authentication design, not an optional afterthought.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org