What this protects, and what it doesn't
Protects
- Against an attacker who cannot defeat your passkey or hardware key and tries the recovery path instead: once text messages and guessable recovery are removed, the easy way around your login is closed.
- Against SIM swapping used to recover an account, not only to sign in, once your phone number is removed as a recovery method.
- Against a stale or weak recovery e-mail being used to take over the account, once that mailbox has its own strong login and is limited to recovery.
- Against a single lost or broken key locking you out, because you register more than one hardware or passkey factor and keep backup codes offline.
Does not protect
- An account whose provider still forces a recovery step you cannot turn off. You can only choose the strongest tier the provider offers, not remove recovery entirely.
- The risk of locking yourself out. Stronger recovery raises it, so this protects nothing if you also lose your backup codes and your spare key: plan the backups first.
- A device already running malware, which can act inside sessions you have already opened no matter how recovery is configured.
- Help-desk or social-engineering recovery at an organisation. A support agent who can reset your account by phone or e-mail is outside your control.
Prerequisites
- You have already replaced passwords and text-message codes with passkeys and at least one hardware security key (see the passkeys and hardware keys guide).
- A safe offline place for backup codes and a spare hardware key, such as a home safe or a password manager, not the mailbox the account protects.
- A separate e-mail address you control, used only for recovery, with its own strong login.
Step by step
-
Map every way back into the account
Your login is only as strong as the weakest way to reset it. Before changing anything, open each important account's security page and write down every recovery and verification method it lists: a recovery phone number, a recovery or alternate e-mail, backup codes, an authenticator app, security keys and any "trusted contact" option.
For each one ask: could an attacker who already knows my name and e-mail use this to get in without my passkey? A phone number an attacker can port to a new SIM, or an old mailbox you no longer guard, is the path they will take. Those are what you fix in the steps below.
-
Lock down your recovery e-mail
Whoever controls the recovery e-mail can usually reset the account, so treat that mailbox as at least as sensitive as the account itself. Use an address that is different from the one you sign in with and that you still check, for example a dedicated address like
alice.recovery@example.comrather than a shared family inbox.Give that mailbox its own passkey or hardware key and its own backup codes, and do not reuse its password anywhere. An attacker who takes a weak recovery mailbox has taken every account that points at it.
-
Remove text messages as a recovery and second factor
Codes sent by text message can be redirected by SIM swapping, where an attacker moves your number to their SIM, and NIST restricts their use for exactly this reason: setting or changing the pre-registered phone number counts as registering a whole new authenticator, and text-message codes are not phishing-resistant. Once you have passkeys, a spare key and backup codes in place, remove your phone number as both a sign-in and a recovery method on every account that lets you.
Do this only after the stronger factors below are set up and tested, because on many accounts the phone number is the last fallback. Microsoft has announced it is phasing out text-message codes for personal accounts for the same reasons.
-
Register more than one strong factor
The main cause of lockout after hardening recovery is having a single factor and losing it. On every account that accepts them, register at least two hardware security keys or passkeys: one for daily use and one kept somewhere safe at home. Add the spare before you remove weaker methods.
Registering a new phone number or a new key is itself the act of adding a credential that can get you in, so keep that list short, deliberate and known to you: review it whenever you set up a new device and remove keys or devices you no longer have.
-
Save backup codes offline
Most providers issue single-use backup codes for when every device and key is unavailable. Generate a set and store it where the account itself cannot reach it: printed and kept at home, or in a password manager that is protected by a different account. Never leave the codes in the mailbox, cloud note or photo library that the same account protects.
If you need a strong, unique password for that password manager, the password generator creates one in your browser.
-
Google: recovery info and Advanced Protection
In your Google Account, open Security, then under How you sign in to Google set Recovery phone and Recovery email. Use a recovery e-mail that differs from your sign-in address; do not use a Google Voice number, since you cannot receive its codes while locked out. Google notes that changing the recovery phone can take up to seven days to take effect, and that a trusted passkey or security key can speed this up.
If you are a likely target, enrol in the Advanced Protection Program at landing.google.com/advancedprotection. It is Google's highest-security tier: sign-in requires a passkey or FIDO security key, downloads are checked more strictly, and only verified apps may reach your account data. Register two keys before you enrol so enrolment does not leave you with one.
-
Apple: Recovery Key and a recovery contact
On iPhone or iPad, open Settings, tap your name, then Sign-In & Security. A Recovery Key is a 28-character code that replaces Apple's standard account-recovery process: turn it on only with a plan, because Apple cannot give it back to you, and losing it together with access to your trusted devices and phone number can lock you out of your Apple Account permanently.
A gentler option on the same screen is Recovery Contacts: choose up to five people you trust who can give you a six-digit code to get back in. A recovery contact never gains any access to your account, only the ability to hand you that code. On a Mac the same settings are under the Apple menu, System Settings, your name, Sign-In & Security.
-
Microsoft: manage how you sign in
Sign in at account.microsoft.com/security and choose Manage how I sign in (the Advanced security options). Select Add a new way to sign in or verify to add a passkey, a security key or an authenticator app, then expand an old method and choose Remove to drop it. You can keep up to ten verification methods.
Always add the new method before removing the old one. Microsoft warns that requesting removal of all your security info puts the account into a restricted state for 30 days as a safeguard, during which you cannot change security or billing settings.
-
Test recovery, then write down your lockout plan
Stronger recovery means a higher chance of locking yourself out, so prove it works before you rely on it. Sign out and sign back in with each passkey and each hardware key, confirm your backup codes are where you think they are, and check that any recovery contact has accepted and knows they may be asked for a code.
Then write a short plan, kept offline: which factors exist, where the spare key and backup codes live, and the order of steps to recover. Review it whenever you change phone, lose a device or add an account.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Hardening sign-in but leaving a text-message number as a recovery method, so the attacker resets the account by phone instead of defeating the passkey.
- Removing every recovery method at once and landing in a provider's restricted state, or losing access entirely.
- Keeping backup codes in the mailbox, cloud note or photo library that the same account protects.
- Turning on an Apple Recovery Key with no spare key and no recovery contact, then losing the key and being locked out for good.
- Pointing recovery at an e-mail address that is weaker than, or shared with more people than, the account it is meant to protect.
Going further
If your threat model is High, prefer device-bound passkeys on hardware keys for every account that holds or resets the others (e-mail, cloud, password manager, work), enrol in the strongest protection tier each provider offers, and keep the spare key in a separate physical location from the daily one. Review your registered devices and recovery methods on a set date, and after any phone change, house move or change in who you trust. Remember that an organisation's help desk can often reset an account regardless of your settings, so for work accounts, ask your security team how recovery is handled and whether social-engineering a reset is possible.