Can a Google Workspace Administrator Generate Backup Codes for an Employee? Complete 2-Step Verification Recovery Guide
Two-Step Verification (2SV) is one of the most important security controls in Google Workspace. It protects an employee's account even when their password ha...
Two-Step Verification (2SV) is one of the most important security controls in Google Workspace. It protects an employee's account even when their password has been compromised by requiring an additional verification method during sign-in.
But what happens when an employee loses their phone, replaces their device, cannot access Google Authenticator, loses a security key, or otherwise cannot complete 2-Step Verification?
A common question for IT administrators is:
Can a Google Workspace administrator generate backup codes for an employee?
Yes. Google Workspace provides administrators with account-recovery capabilities that can include generating backup verification codes for users enrolled in 2-Step Verification.
However, administrator permissions matter. An administrator may be able to generate codes for ordinary users while being unable to generate them for another administrator. Super administrators have broader recovery capabilities.
This article explains how administrator-generated backup verification codes work, when they should be used, their security implications, and what administrators should do after restoring an employee's access.
What Are Google Backup Verification Codes?
Backup codes are one-time codes that can be used as an alternative verification method when a user cannot access their normal 2-Step Verification method.
For example, an employee may normally sign in using:
- Google Prompt
- Google Authenticator
- A security key
- A passkey
- SMS or voice verification, where available
- Another configured second factor
If the normal verification method is unavailable, a backup verification code can provide another way to complete authentication.
Google's standard user-generated backup codes are 8-digit codes. Each code can be used only once.
Backup codes should therefore be treated similarly to passwords or other authentication credentials.
Can an Administrator Generate Backup Codes for an Employee?
Yes.
A Google Workspace administrator with the necessary privileges can generate backup verification codes for an employee enrolled in 2-Step Verification.
This feature is particularly important for organizations that enforce 2SV because an employee can otherwise become locked out when the registered second factor is unavailable.
Typical examples include:
Lost phone: The employee's smartphone containing Google Authenticator or receiving Google Prompts has been lost.
Broken phone: The registered phone no longer works.
New phone: The employee replaced their device before properly transferring or configuring authentication methods.
Lost security key: The employee normally uses a physical security key but no longer has access to it.
Unavailable phone number: The employee changed numbers, lost the SIM, or temporarily cannot receive verification messages.
Authenticator unavailable: The user cannot access the Authenticator configuration needed for the account.
In these situations, administrator-generated backup verification codes can provide a controlled recovery path.
Important: User Recovery and Administrator Recovery Are Different
The distinction between an ordinary employee account and an administrator account is important.
An administrator with appropriate permissions can generate or view backup verification codes for users within the scope of their administrative privileges.
However, Google applies stricter rules when the locked account belongs to another administrator.
Only a super administrator can generate backup verification codes for other administrators.
Therefore, an IT support administrator may be able to help:
employee@company.com
but might not have sufficient privileges to recover:
admin@company.com
even though both accounts belong to the same Google Workspace organization.
This restriction helps prevent a lower-level administrator from using account-recovery capabilities to gain access to a more privileged administrator account.
How to Generate Backup Verification Codes for an Employee
The exact wording and placement of options in Google Admin Console can change as Google updates the interface, but the general process is:
- Sign in to the Google Admin console using an authorized administrator account.
- Open Directory.
- Open Users.
- Locate the affected employee.
- Open the employee's account.
- Find the user's security or 2-Step Verification settings.
- Locate the option for Backup verification codes.
- Generate the backup verification codes.
- Provide an unused code to the employee through a secure communication method.
- Have the employee use the code to complete the 2-Step Verification challenge.
Do not send authentication credentials through an insecure or compromised communication channel.
How Does the Employee Use the Administrator-Generated Code?
The employee begins signing in normally with the Google Workspace account.
For example:
employee@company.com
After entering the password, Google requests the second verification step.
If the employee cannot use the normal method, they can select an option such as:
Try another way
and choose the available backup-code option.
The employee then enters an unused backup verification code.
Once accepted, the user can continue the sign-in process.
Backup Codes Are One-Time Credentials
A backup code should not be considered a permanent replacement for Google Authenticator, Google Prompt, a passkey, or a security key.
Backup codes are intended primarily as recovery credentials.
Once a particular backup code has successfully been used, it cannot be used again.
For standard Google Account backup codes, generating a new set also invalidates the previous set.
This prevents an old list of backup codes from remaining indefinitely usable after replacement.
Example Scenario: Employee Loses Their Phone
Consider an organization using Google Workspace with mandatory 2-Step Verification.
An employee normally signs in using:
Email: accounts@company.com
Password: Employee's password
Second factor: Google Prompt on company phone
The employee loses the phone while travelling.
The next morning, the employee attempts to sign in from another computer.
Google accepts the password but requests 2-Step Verification.
The Google Prompt is being sent to the missing phone.
The employee contacts the organization's IT administrator.
The administrator verifies the employee's identity according to company policy and checks whether another approved recovery method is available.
If appropriate, the administrator generates a backup verification code for the employee.
The employee enters the code during the Google sign-in process and regains access.
The IT administrator should then help the employee configure a replacement authentication method.
What Should Be Done After the Employee Regains Access?
Restoring access should be followed by remediation.
For example, if the employee lost a phone, simply providing a backup code solves the immediate login problem but does not address the missing device.
The organization should review the account and, where appropriate:
- Remove or secure the lost device.
- Remove authentication methods associated with a lost device.
- Configure Google Prompt on the replacement phone.
- Reconfigure Google Authenticator where necessary.
- Review registered passkeys and security keys.
- Review recovery information.
- Review recent account activity.
- Change the password if compromise is suspected.
- Generate and securely store appropriate recovery options.
The goal is to restore the employee's normal secure authentication configuration rather than relying continuously on emergency backup codes.
Can an Administrator See an Employee's Google Authenticator Codes?
No.
Administrator-generated backup verification codes should not be confused with Google Authenticator codes.
Google Authenticator generates time-based one-time passwords associated with the authentication secret configured for the account.
An administrator does not normally open Google Admin Console and see the employee's current Authenticator code.
Instead, administrators have specific account-management and recovery capabilities.
This separation is important because administrative recovery should not require administrators to possess an employee's everyday authentication factor.
Can an Administrator Generate Codes Without Knowing the User's Password?
Generating backup verification codes is an administrative function and is separate from knowing the employee's current password.
However, a backup code represents the second verification step. It should not be treated as a replacement for the account password.
The user still needs to satisfy Google's applicable sign-in requirements.
Administrators also have separate password-reset capabilities when authorized.
Therefore, these are two different administrative operations:
Password reset — addresses the password or first authentication credential.
Backup verification code — assists with the 2-Step Verification requirement.
What If the Employee Forgot the Password AND Lost the 2FA Device?
This requires more careful recovery.
The administrator may need to reset the employee's password and separately address the 2-Step Verification problem.
For example:
Problem 1: Employee forgot password.
Solution: Administrator resets the password according to organizational policy.
Problem 2: Employee cannot complete 2-Step Verification.
Solution: Use an approved recovery method, which can include administrator-generated backup verification codes where supported and appropriate.
This distinction is useful when troubleshooting Google Workspace login failures because resetting a password alone does not necessarily resolve a 2SV challenge.
What If a Login Challenge Is Blocking the Employee?
Google can also present security-related login challenges.
A login challenge and 2-Step Verification are related security concepts but should not automatically be treated as the same problem.
Google Workspace provides administrators with tools for troubleshooting sign-in challenges. Depending on the situation and administrator privileges, an administrator may be able to temporarily disable a login challenge.
Google states that changing the user's password alone might not restore access when a login challenge is the actual cause.
Therefore, administrators should identify what is blocking the account:
Incorrect password?
2-Step Verification?
Login challenge?
Suspended account?
Security policy?
Lost authentication method?
The appropriate recovery procedure depends on the answer.
Can a Help Desk Administrator Generate Backup Codes?
Potentially, yes, depending on the administrative privileges and scope assigned to that administrator.
Google Workspace allows organizations to delegate administrative responsibilities instead of making every IT employee a super administrator.
This is preferable from a security perspective.
For example, an organization may create a delegated administrator role that allows help desk staff to perform specific user-management and security-related operations while preventing them from changing organization-wide security settings.
Administrators should follow the principle of least privilege: grant only the permissions required for the person's job.
Can an Administrator Generate Backup Codes for Another Administrator?
This is where the permissions become more restrictive.
Google states that only super administrators can generate backup verification codes for other administrators.
This means an ordinary delegated administrator who can recover employee accounts should not be assumed to have the same capability for:
- Help desk administrators
- Groups administrators
- User management administrators
- Security administrators
- Other delegated administrators
- Super administrators
Recovery of privileged accounts requires additional protection because compromising an administrator account can affect the entire Google Workspace environment.
Why Should Organizations Have More Than One Super Administrator?
Organizations should avoid making a single person's account the only path to critical administrative recovery.
Imagine this situation:
The company has one Google Workspace super administrator.
That administrator's phone is stolen.
The security key is also unavailable.
No usable recovery method exists.
The organization may now face a significantly more complicated administrator-account recovery process.
Maintaining appropriately secured administrative redundancy can reduce this operational risk.
This does not mean every IT employee should be a super administrator.
Super administrator access should remain tightly controlled.
Security Risk: Backup Codes Are Powerful Credentials
Backup codes are designed to bypass the normal second-factor method during authentication.
That makes them sensitive credentials.
Suppose an attacker has already obtained an employee's password.
Normally, 2-Step Verification could prevent the attacker from accessing the account.
But if the attacker also obtains an unused backup code, that additional security barrier may be defeated.
Therefore, backup codes should never be:
- Posted in support tickets unnecessarily.
- Stored in public documents.
- Sent to large group chats.
- Shared through unsecured communication.
- Saved in publicly accessible folders.
- Left printed on desks.
- Included in knowledge-base screenshots.
- Reused after an incident without reviewing security.
Treat them as authentication secrets.
Verify the Employee Before Issuing a Backup Code
This is one of the most important administrative practices.
Suppose someone contacts the IT department and says:
"I lost my phone. Please send me a Google backup code."
The administrator should not automatically provide one.
The request could potentially be a social-engineering attack.
The administrator should verify the employee's identity using the organization's approved identity-verification procedure.
Depending on the organization, verification might involve a known internal communication channel, manager confirmation, corporate identity procedures, or another approved mechanism.
The exact process should be established before an emergency occurs.
Never Ask the Employee to Send Their Password
The administrator should not ask:
"Send me your Google password and I'll log in for you."
That is poor security practice.
Administrative recovery tools exist specifically so that IT administrators can manage account problems without requiring employees to disclose their passwords.
The employee's password should remain confidential.
Employee-Generated Backup Codes vs Administrator-Generated Codes
There are two important scenarios.
Employee-generated backup codes
When 2-Step Verification is configured, users can generate backup codes from their Google Account security settings and securely store them for emergency use.
Google currently provides a set of 10 backup codes, and each code can be used once.
Generating a new set invalidates the previous set.
Administrator-generated backup verification codes
When a managed Google Workspace user becomes locked out because they cannot access their second factor, an authorized administrator can use Google Workspace administrative recovery capabilities to generate backup verification codes.
The first approach is preventive.
The second approach is administrative recovery.
A well-managed organization should consider both.
Should Companies Give Backup Codes to Every Employee in Advance?
Organizations should establish a recovery policy appropriate to their security requirements.
For some environments, employees securely storing their own backup codes can provide useful emergency access.
For higher-security organizations, security keys, passkeys, managed devices, controlled administrative recovery, and stronger authentication policies may be preferred.
The important point is that recovery mechanisms should be designed before users become locked out.
Backup Codes and Google's Advanced Protection Program
Organizations and users should also be aware that authentication capabilities can differ for accounts enrolled in Google's Advanced Protection Program.
Google states that users enrolled in Advanced Protection cannot download standard backup codes.
Administrators should therefore not assume that the same recovery workflow applies to every security configuration.
High-security accounts should have a documented recovery procedure appropriate to the authentication methods being used.
Recommended Google Workspace 2SV Recovery Policy
A business using Google Workspace should establish a documented process covering:
- How employees report lost authentication devices.
- How IT verifies the employee's identity.
- Which administrators can generate backup verification codes.
- How emergency codes are securely communicated.
- How lost devices and authentication factors are revoked.
- How new authentication methods are enrolled.
- How suspicious account activity is investigated.
- How administrator accounts are recovered.
- How backup super administrator access is maintained.
- How recovery events are documented and reviewed.
This converts 2-Step Verification recovery from an improvised help-desk procedure into a controlled security process.
Example IT Help Desk Procedure
An employee calls IT:
Employee: "My phone is broken and I can't access Gmail because Google is asking for verification."
The administrator should first verify the employee's identity.
Next, determine which authentication methods remain available.
Perhaps the employee already has:
- Another signed-in phone
- A passkey
- A security key
- Previously generated backup codes
- Another approved second factor
If none are available, the administrator can use authorized Google Workspace recovery capabilities.
After access is restored, the administrator helps the employee enroll the replacement device and reviews the obsolete authentication method.
This approach is preferable to disabling 2-Step Verification simply because a phone was lost.
Should an Administrator Disable 2-Step Verification Instead?
Usually, administrative recovery should preserve security wherever possible.
Disabling 2-Step Verification can reduce account protection and might conflict with organizational security policy or enforcement settings.
If a backup verification code or another approved recovery mechanism can restore access safely, that may be preferable to broadly weakening the account's authentication requirements.
The exact decision depends on the organization's Google Workspace configuration and security policy.
Backup Verification Codes vs Password Reset
These two functions solve different problems.
| Problem | Typical Administrative Action |
|---|---|
| Employee forgot password | Reset password |
| Employee lost 2FA phone | Use 2SV recovery method |
| Employee lost security key | Use alternate/recovery factor |
| Employee has no normal second factor | Generate backup verification code where appropriate |
| Login challenge blocks access | Investigate/manage login challenge |
| Employee account suspended | Review and unsuspend if appropriate |
| Administrator loses 2SV access | Super-admin/admin recovery procedure |
Administrators should diagnose the actual authentication problem before making changes.
Backup Verification Codes vs Google Authenticator
These are also different technologies.
Google Authenticator
Generates rotating time-based verification codes and is normally configured on a user's device.
Backup code
A recovery credential designed for use when normal authentication methods are unavailable.
Authenticator is intended for normal authentication.
Backup codes are intended primarily for recovery.
Best Practices for Google Workspace Administrators
Organizations enforcing 2-Step Verification should consider several operational safeguards.
Require strong authentication for administrators and high-risk accounts.
Maintain more than one appropriately secured super administrator account.
Use delegated administrator roles for help desk personnel instead of giving everyone super administrator privileges.
Encourage users to configure appropriate backup authentication methods.
Use security keys or passkeys where stronger phishing resistance is required.
Create a documented lost-device procedure.
Verify identity before issuing recovery credentials.
Review authentication methods after every lost-device incident.
Never send passwords and backup codes together through the same insecure communication channel.
Treat administrator-generated backup codes as temporary recovery credentials, not permanent authentication methods.
Frequently Asked Questions
1. Can a Google Workspace administrator generate backup codes for an employee?
Yes. An administrator with appropriate privileges can generate backup verification codes for a managed user enrolled in 2-Step Verification.
2. Can an administrator generate codes when the employee loses their phone?
Yes. This is an important use case for backup verification codes.
3. Does the administrator need the employee's phone?
No. The administrative recovery function is designed to help when the employee cannot use their normal second-factor device.
4. Does the administrator need the employee's password to generate backup codes?
The administrative generation of backup verification codes is separate from knowing the user's current password.
5. Can the backup code replace the employee's password?
No. A backup code is associated with the verification step and should not be considered a replacement for the user's password.
6. Can a regular administrator generate backup codes for another administrator?
Not necessarily. Google states that only super administrators can generate backup verification codes for other administrators.
7. Can a super administrator generate backup codes for another administrator?
Yes, subject to Google's current administrative controls.
8. Can a help desk administrator generate backup verification codes?
It depends on the privileges and administrative scope assigned to the help desk administrator.
9. Can administrators see Google Authenticator codes?
Administrator-generated backup codes are different from the rotating codes generated by Google Authenticator.
10. Are backup codes reusable?
Individual backup codes are intended for one-time use.
11. How many standard backup codes does Google provide?
Google currently allows users to generate a set of 10 backup codes.
12. What happens after one code is used?
That particular code becomes inactive.
13. What happens when a new standard set of backup codes is generated?
Google states that the previous set becomes inactive.
14. Should employees share backup codes with IT?
Backup codes should be treated as sensitive authentication credentials and should not be routinely shared.
15. Can an administrator generate backup codes if 2-Step Verification isn't enabled?
Backup codes are part of 2-Step Verification. The relevant user must be enrolled in 2SV for this recovery mechanism to apply.
16. What should IT do when an employee loses a phone?
Verify the employee's identity, restore access using an approved recovery method, secure or remove the lost device where appropriate, and configure a replacement authentication method.
17. Should IT disable 2-Step Verification when a phone is lost?
Not automatically. Using an approved recovery mechanism can preserve stronger account security.
18. Can resetting the password fix every 2SV lockout?
No. Password authentication and the second verification step are separate. Google also warns that password changes alone do not necessarily resolve login challenges.
19. Can a backup code be used when Google Authenticator is unavailable?
Yes, provided backup-code authentication is available for the account and the user has a valid unused code.
20. What should a user do after signing in with an emergency backup code?
Configure a working authentication method, review security settings, and remove authentication methods associated with lost or compromised devices where appropriate.
21. Should organizations maintain multiple super administrators?
Maintaining appropriately secured administrative redundancy is a good operational practice so that the organization is not dependent on one administrator account.
22. Can backup codes create a security risk?
Yes. Anyone who obtains the necessary account credentials plus a valid backup code could potentially use it to satisfy the 2SV requirement.
23. Should backup codes be stored in plain text?
Organizations should store recovery credentials using appropriately secured systems and restrict access.
24. Can backup codes help after a security key is lost?
They can be one possible recovery mechanism, depending on the account's authentication configuration and policies.
25. Can Advanced Protection users download normal backup codes?
Google states that standard backup-code downloads are unavailable to accounts enrolled in the Advanced Protection Program.
Conclusion
A Google Workspace administrator can generate backup verification codes for an employee, provided the administrator has the required permissions and the user's account is enrolled in 2-Step Verification.
This capability is extremely useful when an employee loses a phone, cannot access Google Authenticator, loses a security key, or otherwise becomes unable to complete the normal second verification step.
However, backup-code generation should be treated as a security-sensitive account recovery operation.
IT teams should verify the employee's identity before providing recovery credentials, securely communicate the code, restore the employee's normal authentication method after access is regained, and investigate any lost or potentially compromised device.
The most important permission distinction is that while delegated administrators may be authorized to generate backup verification codes for users, only super administrators can generate backup verification codes for other administrators.
A well-designed Google Workspace environment should combine strong 2-Step Verification with a documented recovery procedure so that stronger security does not result in unnecessary business disruption when an authentication device is lost.
#GoogleWorkspace #GoogleAdmin #GoogleWorkspaceAdmin #GoogleSecurity #Google2FA #Google2SV #TwoStepVerification #TwoFactorAuthentication #MFA #BackupCodes #BackupVerificationCodes #GoogleAuthenticator #GooglePrompt #GoogleAccountRecovery #WorkspaceSecurity #AccountSecurity #CyberSecurity #ITSecurity #CloudSecurity #IdentitySecurity #Authentication #UserAuthentication #AccountRecovery #GoogleAdminConsole #WorkspaceAdmin #SuperAdmin #HelpDesk #ITSupport #TechSupport #SystemAdministrator #SysAdmin #ITAdministrator #GoogleWorkspaceSupport #GmailSecurity #GmailBusiness #BusinessEmail #ManagedGoogleAccount #SecurityKey #Passkeys #LostPhone #LostAuthenticator #LoginRecovery #LoginSecurity #AccountLockout #SecurityBestPractices #IdentityManagement #AccessManagement #WorkspaceRecovery #GoogleWorkspaceTips #GoogleWorkspaceGuide
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.