Skip to content
GeneralIntermediate

I Lost My Phone and Can’t Access Google Workspace — What Should I Do?

Losing a phone can become an account-access emergency when the phone is used for Google Workspace 2-Step Verification (2SV), Google Prompt, Google Authentica...

BI
Bison Technical Team Enterprise IT specialists
Updated 31 Jul 2026 12 min read 1 total views

Losing a phone can become an account-access emergency when the phone is used for Google Workspace 2-Step Verification (2SV), Google Prompt, Google Authenticator, SMS verification, or a passkey. Fortunately, losing the phone does not automatically mean losing the Google Workspace account.

The correct recovery method depends mainly on whether you are a Google Workspace user, a Workspace administrator, or the only Super Admin of the organization.

Advertisement

This guide covers account recovery, lost-phone security, 2-Step Verification, Google Authenticator, backup codes, administrator intervention, and preventive measures.


Why losing your phone can block Google Workspace access

A typical Google Workspace account might require:

Password → Second verification method → Account access

The second verification method could be a Google Prompt on your phone, Google Authenticator code, SMS or voice code, security key, passkey, or another approved authentication method.

Therefore, you might know the correct email address and password but still be unable to sign in because the second authentication factor was on the lost device.

Google specifically recommends using another available verification method when the primary phone is unavailable.

First priority: secure the lost phone

If the phone is genuinely lost or stolen, account security should be handled alongside account recovery.

From another trusted device where you can access the Google Account, open Google Account → Security & sign-in → Your devices → Manage all devices. Locate the missing phone and sign it out.

Google recommends signing out of a lost or stolen phone and changing the Google Account password. You should also review recent devices and sessions for activity you don't recognize.

For an Android device, Google's device-management capabilities can also help locate, secure, mark as lost, or erase the device when the required conditions are met.

If the phone contained your SIM, contact the mobile carrier promptly to suspend the old SIM and arrange a replacement. Google also identifies transferring your existing number to a replacement phone or SIM as one possible route back to SMS-based verification.


How to regain access to Google Workspace

When the verification screen appears, look for options such as Try another way, I don't have my phone, or an equivalent recovery choice.

Depending on what was configured before the phone was lost, Google may offer another authentication method.

1. Use another phone already signed in to your account

If your Google Account is already signed in on another eligible phone or device, you may be able to verify your identity there.

After successful access, immediately review the account's 2-Step Verification configuration and replace authentication methods associated with the missing device.

2. Use your replacement SIM

Suppose your second-factor method uses SMS and your phone is lost, but you still control the telephone number.

Contact your mobile operator and obtain a replacement SIM/eSIM using the same number. Once activated, verification messages may again be available on the replacement device.

However, do not rely on SMS as your only recovery mechanism going forward.

3. Use a backup code

Backup codes are specifically designed for situations such as losing your phone or being unable to receive your normal 2-Step Verification method.

Google provides sets of backup codes when this feature is configured. Each code can be used once; generating a new set invalidates the previous set.

If you previously printed or securely stored them, sign in with your username and password, choose another verification method, and select the backup-code option when available.

Important: Never send backup codes to someone claiming to be Google Support. Google states that backup codes should not be shared and are intended to be entered during sign-in.

4. Use a security key

If you registered a physical security key as another second factor, connect or present the security key and follow Google's sign-in instructions.

This is one reason businesses should consider registering more than one authentication method for critical administrator accounts.

5. Use a passkey on another device

A passkey stored on another authorized device may provide another route into the account. Google includes a passkey created on another device among the possible alternatives when the primary phone has been lost.

If the lost phone itself contained a passkey, remove that passkey after regaining account access.

6. Try a previously trusted computer

A computer you previously used for the account can be particularly useful.

Google says that when a user previously signed in on a device and selected the option not to be asked again, the user might be able to access the account without the normal second verification step.

Even when recovery is required, using your normal computer, browser, and location can be preferable to attempting recovery from an unfamiliar environment.

Do not clear browser data, remove profiles, reinstall the browser, or unnecessarily sign out of an existing working session while you are locked out elsewhere.


Google Authenticator was on the lost phone — what happens?

A common situation is:

Password known + Google Authenticator unavailable = cannot complete 2SV

Google Authenticator codes are only one possible authentication mechanism. Losing access to Authenticator does not necessarily lock you out if another second factor or recovery method was previously configured.

Try available alternatives such as another signed-in phone, backup codes, security key, passkey, trusted computer, or another verification method offered by Google.

Once access is restored, remove authentication methods associated with the missing phone and configure the replacement device.


Special case: You are a Google Workspace employee/user

For a business-managed Workspace account such as:

employee@company.com

the organization's Workspace administrator may be able to help.

Google's general consumer account recovery instructions specifically note that normal recovery procedures might not work the same way for work, school, or organizational accounts and recommend contacting the administrator.

Contact your IT department or Google Workspace administrator and tell them:

My phone used for Google Workspace verification has been lost, and I cannot complete the sign-in verification.

The administrator can then use the Workspace administration options appropriate to your organization's policies and security configuration.

This is often much easier than trying to treat a managed business account as a personal Gmail recovery case.


Special case: You are the Google Workspace administrator

Suppose an employee loses the phone used for authentication.

Before making changes, the administrator should verify the employee's identity through the organization's established process. Do not weaken account security merely because somebody knows the employee's name, email address, or phone number.

The administrator can then review the affected user's security configuration in the Google Admin console and use the recovery mechanisms available under the organization's current Workspace configuration.

After access has been restored, make sure the lost device and its authentication credentials are no longer trusted.


Critical situation: the only Super Admin lost the phone

This is the scenario organizations should design against.

Suppose the company has only one Super Administrator:

admin@company.com

and that person's only 2-Step Verification method is the lost phone.

Now there may be no second administrator capable of helping the locked-out administrator.

Try all existing alternative methods first: another signed-in device, backup codes, another configured number, security key, passkey, or an existing trusted computer. These are among the alternatives Google identifies for lost-phone situations.

If none works, you may need Google's account recovery/support process and must prove control of the account or organization as requested.

Recovery involving 2-Step Verification can take time because Google must establish that the person requesting access is actually the account owner. Google's documentation notes that some recovery situations involving loss of the second factor can take several business days.

This is why a business should never make one phone the single point of failure for Workspace administration.


What should you do immediately after recovering the account?

Account recovery is only half the job. The missing device should be treated as a potential security incident.

A practical post-recovery sequence is:

  1. Change the Google Account password, especially if the device was stolen or could have been unlocked.
  2. Sign the missing phone out of the Google Account.
  3. Review Your devices and terminate suspicious sessions.
  4. Remove passkeys or authentication credentials associated with the missing phone.
  5. Configure 2-Step Verification on the replacement device.
  6. Generate a fresh set of backup codes and store them securely.
  7. Add another appropriate recovery/authentication method.
  8. Review recovery phone and recovery email information.
  9. Check Gmail and account activity for anything suspicious.
  10. For Workspace environments, inform the IT administrator and follow the organization's lost-device procedure.

Google recommends reviewing devices and signing out sessions you no longer trust.


Should I change my Google Workspace password?

For a genuinely lost or stolen phone, changing the password is a sensible security response, and Google's lost-phone 2-Step Verification guidance specifically recommends changing the Google Account password.

However, remember that changing the password does not physically recover the phone, revoke every possible credential by itself, or replace a proper review of devices and authentication methods.

Use password change as part of the incident response rather than the entire response.


Should I remotely erase the phone?

Remote erasure is a stronger action and should be considered when the device is unlikely to be recovered or contains sensitive corporate information.

For managed work devices, Google notes that administrators may have device-management capabilities depending on how the device and organization are configured. Google also warns that erasing a device can remove work and personal information, so organizations should follow their device-management policy.

For Android devices, Google's lost-device capabilities can include locking, marking the device lost, signing accounts out, and erasing device data.


A better Google Workspace 2FA strategy for businesses

Businesses should design authentication around the assumption that phones will eventually be lost, damaged, replaced, reset, or stolen.

A better design is:

Primary authentication

Password/passkey + strong second-factor mechanism

Backup authentication

A second approved authentication mechanism independent of the primary phone

Emergency recovery

Backup codes securely stored outside the phone

Administrative redundancy

More than one appropriately protected Super Admin account

The important principle is that your primary authentication device and emergency recovery mechanism should not exist only on the same phone.

For example, keeping Google Authenticator and a screenshot of every backup code on the same phone provides poor disaster recovery. Losing that one device could remove both authentication routes simultaneously.

Google recommends configuring backup methods precisely to reduce the chance of getting locked out when the primary phone is unavailable.


Recommended policy for Google Workspace administrators

For organizations, consider establishing a written Lost Phone / Lost 2FA Device Procedure.

Employees should know whom to contact immediately. Administrators should have a process for verifying the user's identity before modifying authentication settings. Critical administrator accounts should have independent backup authentication mechanisms.

The organization should also periodically review registered devices, recovery information, administrator accounts, and 2-Step Verification enrollment.

This turns a lost phone from a business emergency into a routine account-recovery procedure.


Common mistakes to avoid

Do not repeatedly experiment with security settings while you still have a working logged-in session on another computer. That existing session could be your easiest route to recovery.

Do not store your only backup codes on the phone that provides your primary authentication.

Do not share passwords, OTPs, backup codes, security-key information, or recovery codes with callers or messages claiming they can "unlock Google Workspace."

Do not disable 2-Step Verification permanently just because one phone was lost. Restore access, replace the missing authentication method, and maintain strong authentication.

And for a business domain, do not rely on one person, one Super Admin account, one phone, and one authentication method.


FAQ

1. I lost my phone. Is my Google Workspace account also lost?

No. The account still exists. The problem is proving your identity during authentication. Another configured verification or recovery method may restore access.

2. I know my password. Why can't I log in?

If 2-Step Verification is enabled, the password is only one authentication factor. Google may still require the second factor.

3. Can I log in without Google Authenticator?

Potentially, yes. Depending on your account configuration, alternatives can include another signed-in phone, backup code, security key, passkey, another number, or trusted device.

4. Can my Google Workspace administrator recover my account?

For an organization-managed account, your administrator should be one of your first contacts. Google's consumer recovery documentation specifically advises Workspace users to contact their administrator when appropriate.

5. What if I am the Google Workspace Super Admin?

Try all previously configured backup authentication methods first. If another Super Admin exists, that administrator may be able to assist according to your Workspace security configuration.

6. What if I am the only Super Admin?

This can become a more difficult recovery case. Use any backup method already configured and follow Google's recovery/support process where necessary. After recovery, configure administrative redundancy.

7. Can I use my old phone number on a new phone?

If you still own the number, your mobile carrier may be able to issue a replacement SIM/eSIM. Google identifies transferring the number to a new phone or SIM as an option in lost-phone scenarios.

8. Can I use backup codes?

Yes, provided they were generated beforehand and remain valid. Each backup code can be used once.

9. Should I change my password?

For a lost or stolen phone, Google recommends signing the phone out and changing the Google Account password.

10. Should I remove the lost phone from my Google Account?

Yes. Review Security & sign-in → Your devices → Manage all devices and sign out the missing device.

11. Can someone access Gmail simply because they found my phone?

Not necessarily. Device screen locking, authentication configuration, account sessions, device security, and other controls matter. Nevertheless, a missing authenticated device should be treated as a security risk.

12. Should I disable 2-Step Verification after recovering the account?

Generally, no. A better response is to configure multiple secure authentication and recovery mechanisms so losing one device doesn't lock you out.

13. Where should backup codes be stored?

Store them somewhere secure and independent of the primary phone, such as an appropriate password manager, secure corporate credential system, or protected physical copy.

14. Can I remotely sign out the lost phone?

Yes. Google provides device/session management where you can review devices and sign out a lost device.

15. What is the best protection against this happening again?

Avoid a single point of failure: use multiple appropriate authentication methods, safely store backup codes, maintain current recovery information, and ensure business-critical Workspace administration has suitable administrator redundancy.

Official Google resources

Google: Fix common issues with 2-Step Verification

Google: See devices with account access

Google: Sign in with backup codes

Google: Recover your Google Account or Gmail

 

#GoogleWorkspace #GoogleWorkspaceSecurity #GoogleWorkspaceAdmin #GoogleWorkspaceHelp #GoogleWorkspaceSupport #GoogleAccount #GoogleAccountRecovery #GoogleSecurity #GoogleAuthenticator #Google2FA #TwoFactorAuthentication #2FA #2StepVerification #MFA #AccountRecovery #LostPhone #StolenPhone #LostDevice #AccountSecurity #CyberSecurity #CyberSafety #DataSecurity #CloudSecurity #IdentitySecurity #AccessManagement #Authentication #Passkeys #SecurityKey #BackupCodes #GooglePrompt #GmailSecurity #GmailRecovery #WorkspaceAdmin #SuperAdmin #ITAdmin #ITSupport #TechSupport #BusinessSecurity #BusinessIT #DeviceSecurity #MobileSecurity #AndroidSecurity #SecurityAwareness #InformationSecurity #DigitalSecurity #CloudComputing #GoogleAdmin #WorkspaceSecurity #AccountProtection #ITSecurity

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

BISON AI

Ask about “I Lost My Phone and Can’t Access Google Workspace — What Should I Do?”

This interface is ready to connect to your preferred AI provider. No article or user data is sent until that service is configured.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.