How to Use Google Workspace Backup Codes When Your Phone Is Lost: Complete 2-Step Verification Recovery Guide
Losing the phone used for Google Workspace 2-Step Verification (2SV) can create an immediate access problem, especially when Google Prompt, SMS verification,...
Losing the phone used for Google Workspace 2-Step Verification (2SV) can create an immediate access problem, especially when Google Prompt, SMS verification, or Google Authenticator was your normal second factor.
Fortunately, if you generated and securely stored Google backup codes before losing the phone, you may be able to sign in without the lost device.
This guide explains what Google backup codes are, how to use them with a Google Workspace account, what happens after a code is used, how to secure the account after recovering access, and what options remain if you cannot find your backup codes.
What Are Google Backup Codes?
Backup codes are emergency verification codes associated with Google 2-Step Verification.
They are intended for situations where your normal second verification method is unavailable—for example:
- Your phone is lost or stolen.
- Your phone is damaged.
- Google Authenticator is unavailable.
- You cannot receive SMS or voice verification codes.
- You changed your phone number.
- Your primary authentication device is temporarily unavailable.
Google currently provides a set of 10 backup codes, with each code containing 8 digits.
Each backup code is single-use. Once a particular code has successfully been used for authentication, that code becomes inactive.
Generating a new set also invalidates the previous set.
How to Sign In to Google Workspace Using a Backup Code
Suppose your Google Workspace address is:
employee@example.com
Your phone is lost, but you still know the account password and previously stored your backup codes.
Step 1: Start the Normal Google Sign-In
Open the Google service you need, such as Gmail, Drive, Calendar, or the Google Workspace sign-in page.
Enter your Google Workspace email address and continue.
Enter your password normally.
Google will then request your configured second verification step.
Step 2: Select "Try another way"
Because your phone is unavailable, you cannot approve the Google Prompt or obtain the normal verification code.
Look for:
Try another way
The wording displayed by Google can vary depending on the account, device, authentication methods configured, and security policies applied by the Workspace administrator.
Step 3: Choose the Backup Code Option
Among the available verification methods, look for an option similar to:
Enter one of your 8-digit backup codes
Select it.
Google will provide a field where you can enter one of your previously generated codes.
Step 4: Find Your Stored Backup Codes
When backup codes were originally generated, you may have printed them, downloaded them, or stored them in an approved secure location.
Google notes that a downloaded backup-code file can have a filename similar to:
Backup-codes-username.txt
Therefore, searching your computer for:
Backup-codes-
may help locate a previously downloaded copy.
Do not assume that finding an old backup-code file means its codes are still valid. If another set was generated afterward, the older set was invalidated.
Step 5: Enter One Unused 8-Digit Code
For example, suppose your backup-code list contains codes such as:
1234 5678
This is only an illustration and is not a real backup code.
Enter one unused code into Google's backup-code field and continue.
If the code is valid and the sign-in is otherwise accepted, Google can use it as the second verification step.
What Happens to the Backup Code After You Use It?
The backup code becomes inactive after it is used.
It cannot be reused for another login.
For example, imagine that your original set contains 10 codes.
You use Code #1 to recover access after losing your phone.
Code #1 is now unusable, while the remaining unused codes can remain available.
It is therefore useful to mark a printed code as USED after successful authentication.
Never reuse or rely on a code that has already been consumed.
What Should You Do Immediately After Signing In?
Getting into the account is only the first part of the recovery process.
If the phone has actually been lost or stolen, review the account's security configuration immediately.
1. Remove or secure the lost device
Review devices associated with the Google Account and sign the account out of the lost device where appropriate.
If the device is company-managed, the organization's administrator should also review the applicable endpoint-management controls.
2. Change the password when appropriate
Google recommends changing the Google Account password when a phone has been lost or stolen.
This is particularly important if there is any possibility that another person could unlock the lost phone or access stored credentials.
Use a strong password that is not reused on another service.
3. Configure your replacement phone
Once you have a replacement device, configure your intended 2-Step Verification methods.
Depending on the organization's configuration and Google's available options, these could include:
Google Prompt, Google Authenticator, passkeys, security keys, or another approved verification method.
The exact methods available to a Workspace user can depend on administrator security policies.
4. Review your phone number
If your old mobile number is no longer under your control, remove or replace it where applicable.
A number that has been reassigned to somebody else should not remain an account recovery or verification method.
5. Generate fresh backup codes
After recovering from a lost-phone incident, consider replacing the old backup-code set.
Go to your Google Account's security settings, open 2-Step Verification, and locate Backup codes.
Generating a fresh set invalidates the previous set.
This can be desirable after a security incident because you may not know whether the previous codes were stored on the missing device or somewhere accessible to another person.
Important: Backup Codes Must Normally Exist Before You Need Them
Backup codes are primarily a preparedness mechanism, not something you should expect to create after becoming completely locked out.
If your only second factor was your lost phone, you are signed out everywhere, and you don't possess previously generated backup codes, you cannot simply request a backup code from the login page.
You must use another verification/recovery option available to the account or obtain assistance from your Workspace administrator where applicable.
What If I Never Generated Backup Codes?
Try Try another way during authentication.
Depending on your configuration, Google may offer alternatives such as:
- Another device already signed in to the account
- A backup phone number
- A previously generated backup code
- A registered hardware security key
- A passkey available on another device
- A trusted device/session
- Account recovery where applicable
For a work, school, or organizational Google Workspace account, Google specifically recommends contacting the organization's administrator when sign-in cannot be completed.
What If My Backup Codes Are on the Lost Phone?
Treat those codes as potentially compromised.
If you still have account access through another authenticated computer, passkey, security key, or other verification method, open your 2-Step Verification settings and generate a new backup-code set.
Generating new codes invalidates the previous set.
This is important because backup codes should be treated like credentials.
Someone who obtains your password and a valid unused backup code may potentially have what they need to satisfy password-plus-second-factor authentication.
Can I Reuse a Google Backup Code?
No.
A backup code becomes inactive after successful use.
Suppose you have:
Code ACode BCode C
You use Code A during an emergency login.
For the next backup-code login, use Code B or another unused code—not Code A.
How Many Google Backup Codes Do I Get?
Google currently allows users to generate a set of 10 backup codes.
Each is an 8-digit code.
When you generate a new set, the previous set automatically becomes inactive.
This means you should replace the stored copy whenever you regenerate your codes.
Otherwise, you might discover during an emergency that the codes in your old printed or downloaded list are no longer valid.
Where Should Backup Codes Be Stored?
Backup codes should be available during an emergency without being unnecessarily exposed.
Possible approaches include storing them in:
- A secure physical location
- An approved enterprise password manager or secure vault
- A protected offline document
- A securely stored printed copy
Avoid leaving the only copy on the same phone used for authentication.
For example, storing Google Authenticator, the Google account session, and the only backup-code screenshot on one phone creates a single point of failure.
Lose that phone, and all three recovery mechanisms may disappear simultaneously.
Should I Email Backup Codes to Myself?
Generally, avoid storing the only copy of the backup codes inside the same Google account they are supposed to help recover.
Imagine:
user@example.com
has backup codes stored only in that account's Gmail mailbox or Google Drive.
If the user becomes completely locked out, those codes may be inaccessible precisely when they are needed.
A backup should remain independently accessible.
Google Workspace Administrators: Prepare Before Users Lose Their Phones
Organizations using Google Workspace should consider account-recovery planning part of their security policy.
Administrators should ensure that users understand which 2-Step Verification methods are permitted and what to do when a device is lost.
A resilient setup might include a primary authentication method plus one or more administrator-approved backup mechanisms.
The objective is not to weaken 2-Step Verification. It is to prevent one lost device from becoming the organization's only path to an important account.
This is especially important for administrators and other privileged accounts.
Special Warning for Google Workspace Super Admin Accounts
A Super Admin account can control users, security settings, organizational policies, and other critical Workspace resources.
Its recovery plan should therefore be stronger than that of an ordinary account.
Avoid creating a situation where one administrator's phone is the organization's only usable authentication mechanism for a critical administrative account.
Organizations should plan administrator access and recovery according to their security requirements and Google's current Workspace recommendations.
Backup Codes vs Google Authenticator
These mechanisms serve different purposes.
Google Authenticator generates time-based verification codes and is suitable for routine authentication.
Backup codes are pre-generated emergency codes designed for circumstances where your normal second step is unavailable.
Backup codes should therefore not normally replace your everyday authentication method.
Think of them as emergency access credentials.
Backup Codes vs SMS Verification
SMS verification depends on access to the registered phone number and mobile network.
Backup codes do not require receiving a new SMS during the sign-in attempt.
Therefore, a previously stored backup code can be particularly useful when the phone is lost, the SIM is unavailable, or mobile service cannot be accessed.
However, the backup code must already exist and remain valid.
Backup Codes vs Passkeys
A passkey can provide passwordless authentication using an approved device and its authentication mechanism, such as a device screen lock or biometric verification.
Backup codes are different: they are emergency numeric credentials used as an alternative second verification step in applicable sign-in flows.
A well-designed recovery strategy may use multiple independent methods rather than relying entirely on one phone.
What If Google Says the Backup Code Is Invalid?
Check several possibilities.
First, make sure the code has not already been used.
Second, verify that the code belongs to the Google account you are attempting to access.
Third, consider whether you generated a new backup-code set after saving the copy you are currently using. Generating a new set invalidates the old set.
If you have multiple Google accounts, do not mix their backup-code files.
What If All 10 Backup Codes Have Been Used?
If you can still access the account, generate a new set from your Google Account security settings.
Do not wait until you are locked out.
Once new codes are generated, securely replace the old stored copy.
What If My Phone Was Stolen Rather Than Lost?
Treat a stolen phone as a security incident.
After obtaining access through a backup method, review the account's devices, remove the lost device as appropriate, change the password where warranted, review verification methods, and replace potentially exposed backup codes.
Also use the applicable device-management or remote-device security controls available for the phone and your organization.
Can a Google Workspace Administrator See My Backup Codes?
Backup codes are authentication credentials and should not be treated as ordinary administrator-readable information.
Users should never send backup codes to IT support personnel, colleagues, or anyone claiming that the codes are required for troubleshooting.
Google explicitly warns users not to share backup codes and says Google does not ask for them except during sign-in.
Never Give Backup Codes to Someone Who Contacts You
A common phishing scenario may look like this:
"We detected suspicious activity. Send us one of your backup codes to verify your account."
Do not do this.
Backup codes are meant to be entered into Google's legitimate authentication flow—not supplied to a person by email, chat, phone call, messaging application, or support ticket.
Treat every unused backup code like a sensitive authentication credential.
Recommended Google Workspace Recovery Design
For important Workspace accounts, avoid depending on a single phone.
A stronger recovery strategy can include:
Primary method: An organization-approved phishing-resistant authentication method where practical.
Secondary method: Another approved authentication method or device.
Emergency method: Securely stored backup codes where supported and appropriate.
Administrative recovery: Documented procedures for users who lose all normal authentication methods.
For privileged administrator accounts, recovery procedures should be documented and tested before an emergency occurs.
Example Lost-Phone Recovery Scenario
Consider an employee called Alex using:
alex@example.com
Alex's password is known, but the phone containing the normal verification method is lost.
Fortunately, Alex previously printed the Google backup codes and stored them securely.
The recovery process is:
Google sign-in → Enter email → Enter password → Try another way → Enter an 8-digit backup code → Sign in
After access is restored, Alex reviews the lost device, updates authentication methods for the replacement phone, checks security settings, and generates a fresh set of backup codes if the old set could have been compromised.
This is exactly the type of emergency backup codes are designed to address.
Frequently Asked Questions (FAQ)
1. Can I access Google Workspace without my lost phone?
Potentially, yes. If you have another valid authentication method, such as a previously saved backup code, you may be able to complete 2-Step Verification without the lost phone.
2. Where do I enter a Google backup code?
After entering your password, choose Try another way and select the option to enter one of your 8-digit backup codes.
3. How many backup codes does Google provide?
Google currently provides a set of 10 backup codes.
4. How many times can one backup code be used?
Once. After successful use, that code becomes inactive.
5. How long is a Google backup code?
Google's backup codes are currently 8-digit codes.
6. Do backup codes require my phone?
No. That is one of their primary advantages during a lost-phone situation.
7. Do backup codes require SMS?
No. A previously generated backup code can be entered directly during the applicable Google sign-in flow.
8. Can I use a backup code when Google Authenticator is unavailable?
Yes, provided backup codes were configured, you have an unused valid code, and the sign-in flow permits that method.
9. Can I generate backup codes after losing my phone?
Yes, if you can still authenticate to the account through another available method. If you are completely locked out, you cannot rely on generating new backup codes as the recovery method.
10. Does creating new backup codes invalidate the old ones?
Yes. Google states that generating a new set makes the previous set inactive.
11. What should I do if my backup codes were stored on the stolen phone?
If you can access the account through another method, generate a new set so the previous codes become inactive.
12. Can I print my backup codes?
Yes. Google provides options to print or download backup codes.
13. Can I store backup codes in Google Drive?
Technically, a file can be stored there, but relying on the same locked account as the only location for its recovery codes defeats much of their emergency value.
14. Can my Google Workspace administrator help if I am locked out?
For organizational accounts, Google recommends contacting your administrator if you cannot sign in.
15. What if I have no phone and no backup codes?
Try other authentication options shown under Try another way. If none are available, Workspace users should contact their administrator.
16. Can a used backup code become valid again?
No. Use another unused code.
17. Can I use backup codes on a new computer?
They are associated with the Google account rather than being intended only for the original computer. Google's security systems may still apply additional protections to a sign-in.
18. Should I keep backup codes on my phone?
Do not make the authentication phone the only place where the codes are stored. Losing one device should not eliminate both your primary and emergency authentication methods.
19. Should a Super Admin maintain backup authentication options?
Yes. Privileged administrative accounts should have carefully planned recovery mechanisms consistent with the organization's security policies.
20. Are backup codes the same as Google Authenticator codes?
No. Authenticator normally generates rotating time-based codes. Backup codes are pre-generated emergency codes, and each backup code is single-use.
Conclusion
Google Workspace backup codes are an important emergency component of 2-Step Verification.
When a phone is lost, an unused backup code can allow a user to complete the second verification step without needing access to that phone.
The key requirement is preparation.
Generate recovery options before an incident occurs, keep backup codes somewhere secure and independently accessible, and avoid putting every authentication and recovery mechanism on one device.
After recovering an account following a lost or stolen phone, review the device list, secure the account, configure replacement authentication methods, and replace any backup codes that may have been exposed.
For organizations, especially those using privileged Workspace administrator accounts, account recovery should be documented as part of the security and business-continuity plan.
#GoogleWorkspace #GoogleBackupCodes #Google2FA #Google2SV #TwoStepVerification #GoogleSecurity #WorkspaceSecurity #GoogleAccount #AccountRecovery #LostPhone #PhoneLost #GoogleAuthenticator #Authenticator #GmailSecurity #GmailRecovery #GoogleRecovery #BackupCodes #SecurityCodes #VerificationCode #Authentication #TwoFactorAuthentication #2FARecovery #AccountSecurity #CyberSecurity #GoogleAdmin #WorkspaceAdmin #GoogleWorkspaceAdmin #SuperAdmin #ITAdmin #ITSupport #TechSupport #GoogleSupport #WorkspaceSupport #GoogleLogin #LoginRecovery #LostDevice #DeviceSecurity #IdentitySecurity #AccessSecurity #SecurityGuide #ITSecurity #GoogleTips #WorkspaceTips #GmailTips #AuthenticationSecurity #Passkeys #SecurityKey #BusinessSecurity #CloudSecurity #GoogleWorkspaceSecurity
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.