Skip to content
GeneralBeginner

How Can a Google Workspace Admin Help a User Locked Out by 2FA? Complete Administrator Guide (2026)

Two-Step Verification (2SV), also known as Two-Factor Authentication (2FA), is one of the most important security features in Google Workspace. It significan...

BI
Bison Technical Team Enterprise IT specialists
Updated 02 Aug 2026 6 min read 0 total views

Two-Step Verification (2SV), also known as Two-Factor Authentication (2FA), is one of the most important security features in Google Workspace. It significantly reduces the risk of unauthorized account access by requiring users to verify their identity with a second factor such as the Google Authenticator app, Google Prompt, security keys, backup codes, or phone verification.

However, users occasionally become locked out because they:

Advertisement
  • Lost their mobile phone
  • Changed devices without transferring Google Authenticator
  • Deleted the Authenticator app
  • Lost backup codes
  • Security key is unavailable
  • SIM card is damaged or changed
  • Google Prompt isn't appearing
  • Company-issued phone is broken
  • Forgot where backup codes were stored

In these situations, a Google Workspace administrator can assist the user in regaining account access safely without compromising organizational security.

This article explains every administrator option available, when to use it, best practices, and common mistakes to avoid.


What Causes a User to be Locked Out?

A user may be unable to complete the second verification step because:

  • Lost smartphone
  • Phone factory reset
  • New phone without migrated Authenticator
  • Security key misplaced
  • Backup codes unavailable
  • Phone number changed
  • Device stolen
  • Google Prompt disabled
  • Authenticator app deleted
  • Hardware failure

Although the password is correct, Google refuses login because the second authentication factor cannot be verified.


Can a Google Workspace Admin Bypass 2FA?

No.

Google Workspace administrators cannot view:

  • One-Time Passwords (OTP)
  • Google Authenticator codes
  • Backup codes
  • Security Keys
  • Recovery codes

Google intentionally prevents administrators from seeing users' authentication secrets.

Instead, administrators can:

  • Reset 2-Step Verification
  • Allow temporary access
  • Help users re-enroll
  • Remove old verification methods
  • Enforce new enrollment

Administrator Recovery Options

Depending on the situation, administrators have several recovery methods.

Option 1: Reset User's 2-Step Verification (Most Common)

This is the quickest recovery method.

What happens?

Google removes:

  • Authenticator app registration
  • Security keys
  • Google Prompt devices
  • Phone verification methods
  • Backup codes

The user signs in with only their password.

They must then configure 2-Step Verification again.

Steps

  1. Open Google Admin Console.
  2. Go to Directory → Users.
  3. Select the affected user.
  4. Open Security.
  5. Click 2-Step Verification.
  6. Choose Reset 2-Step Verification.
  7. Confirm.

The user can now sign in and set up 2SV again.


Option 2: Generate Temporary Backup Codes

If available under your organization's policies, administrators may guide users to use existing backup codes that were previously generated and safely stored by the user.

These codes:

  • Work once each
  • Bypass phone authentication
  • Should be replaced after use

Option 3: Remove Lost Devices

If a phone has been:

  • Lost
  • Sold
  • Stolen
  • Factory reset

Administrators should advise the user to remove old trusted devices after regaining access.

This prevents unauthorized approval requests.


Option 4: Help Reconfigure Authentication

After login:

Configure one or more:

  • Google Authenticator
  • Google Prompt
  • Passkeys
  • Security Keys
  • Backup Codes
  • Recovery Phone

Never leave only one authentication method configured.


Option 5: Security Investigation

If the device was stolen, administrators should investigate:

  • Recent login activity
  • Suspicious devices
  • Unknown IP addresses
  • Login attempts
  • Security alerts

If suspicious activity exists:

  • Reset password
  • Reset 2SV
  • Revoke sessions
  • Remove OAuth apps
  • Review audit logs

Step-by-Step Admin Reset Procedure

Step 1

Sign into Google Admin Console.


Step 2

Open:

Directory → Users


Step 3

Choose the affected account.


Step 4

Open Security.


Step 5

Locate:

2-Step Verification


Step 6

Click:

Reset 2-Step Verification


Step 7

Confirm the warning.


Step 8

Notify the user.

The next login requires:

  • Password
  • New 2SV enrollment

What Happens After Reset?

The user signs in using their password.

Google immediately requests:

  • New Authenticator setup
  • New Google Prompt
  • New Security Key (optional)
  • New backup codes

Old authentication methods become invalid.


What If the User Forgot Their Password Too?

The administrator should:

  1. Reset the user's password.
  2. Reset 2-Step Verification.
  3. Require password change at next login.
  4. Ask the user to enroll in 2SV again.

What If 2SV is Enforced Organization-Wide?

No problem.

Even if mandatory 2-Step Verification is enabled:

  • Admin resets the user's enrollment.
  • User signs in.
  • Google requires immediate re-enrollment.

Security policy remains intact.


Best Practices After Recovery

Always recommend users:

  • Generate backup codes.
  • Print backup codes.
  • Store codes securely.
  • Configure Google Prompt.
  • Add a security key.
  • Register more than one device.
  • Keep recovery phone updated.
  • Keep recovery email current.
  • Enable passkeys where supported.

Administrator Security Checklist

✔ Verify the user's identity before resetting 2SV.

✔ Confirm the recovery request through company-approved channels.

✔ Reset the password if account compromise is suspected.

✔ Review login history.

✔ Remove suspicious devices.

✔ Review third-party app access.

✔ Require immediate 2SV re-enrollment.

✔ Encourage multiple recovery methods.

✔ Document the support action if required by company policy.


Common User Mistakes

  • Using only one phone for authentication
  • Never generating backup codes
  • Ignoring recovery phone setup
  • Factory resetting phones without transferring Authenticator
  • Losing security keys
  • Saving backup codes on the same phone
  • Sharing backup codes
  • Disabling recovery information

Common Administrator Mistakes

  • Resetting 2SV without identity verification
  • Leaving users without re-enrollment
  • Ignoring suspicious login alerts
  • Not resetting passwords after theft
  • Forgetting to review audit logs
  • Removing security features unnecessarily

Security Recommendations

For organizations:

  • Require 2-Step Verification for all users.
  • Require hardware security keys for privileged accounts.
  • Use passkeys where possible.
  • Train employees on backup code storage.
  • Maintain an identity verification process for help desk requests.
  • Periodically review recovery methods and enrolled devices.
  • Monitor login alerts and audit logs regularly.

Troubleshooting

User still cannot log in after reset

Possible reasons:

  • Incorrect password
  • Password reset required
  • Browser cache issue
  • Account suspended
  • Login challenge still pending

Google Prompt never appears

Check:

  • Internet connection
  • Signed-in Google account
  • Notifications enabled
  • Prompt device online

Authenticator codes fail

Possible reasons:

  • Incorrect device time
  • Wrong Google account
  • Authenticator not transferred correctly

Security key not recognized

Try:

  • Different USB port
  • NFC instead of USB
  • Updated browser
  • Register a replacement key after account recovery

Frequently Asked Questions (FAQ)

1. Can a Google Workspace admin disable 2-Step Verification for a specific user?

Yes. An administrator can reset or disable a user's 2-Step Verification enrollment according to organizational policies, allowing the user to regain access and then re-enroll.

2. Can an admin see a user's Google Authenticator codes?

No. Google never exposes authentication codes, backup codes, or security keys to administrators.

3. Does resetting 2-Step Verification delete user data?

No. Resetting 2SV only removes enrolled second-factor methods. Emails, Drive files, Calendar events, and other Workspace data remain unchanged.

4. Does the user need to set up 2SV again?

Yes. After a reset, the user must enroll a new authentication method before continuing if 2SV is required.

5. What if the user's phone was stolen?

Reset the password, reset 2SV, review recent login activity, revoke suspicious sessions, and help the user configure new authentication methods.

6. Can backup codes help if the phone is lost?

Yes. Previously generated backup codes can be used to sign in when the primary second factor is unavailable.

7. Can an admin recover deleted backup codes?

No. Administrators cannot view or recover a user's backup codes. The user must generate a new set after regaining access.

8. Is it safe to reset 2-Step Verification remotely?

Yes, provided the administrator first verifies the user's identity using approved company procedures.

9. Does resetting 2SV affect other users?

No. The action only impacts the selected user's account.

10. Should administrators verify identity before resetting 2SV?

Absolutely. Identity verification is a critical security step to prevent unauthorized account recovery.


Conclusion

Google Workspace provides administrators with secure tools to help users who are locked out by 2-Step Verification without weakening the platform's security model. While administrators cannot bypass or view authentication codes, they can reset a user's 2SV enrollment, assist with password recovery, investigate suspicious activity, and guide users through securely re-enrolling their authentication methods. Establishing a documented recovery process, verifying user identity, and encouraging multiple recovery options—such as backup codes, passkeys, and security keys—helps organizations minimize downtime while maintaining strong account protection.

 

#GoogleWorkspace #GoogleAdmin #TwoStepVerification #2FA #MFA #GoogleAuthenticator #GooglePrompt #CyberSecurity #CloudSecurity #AccountRecovery #GoogleSecurity #WorkspaceAdmin #ITSupport #SystemAdministrator #GoogleCloud #BusinessSecurity #IdentityManagement #ZeroTrust #Authentication #SecurityKey #Passkeys #BackupCodes #WorkspaceSupport #GoogleTips #TechSupport #EnterpriseIT #CloudComputing #GoogleAccounts #DataProtection #InformationSecurity #BusinessIT #AdminConsole #WorkspaceSecurity #ITAdmin #GoogleHelp #NetworkSecurity #LoginIssues #PasswordRecovery #AccessManagement #UserManagement #Compliance #SecurityAwareness #GoogleWorkspaceAdmin #EndpointSecurity #DigitalSecurity #BusinessProductivity #ITInfrastructure #KnowledgeBase #TechArticle #BisonInfosolutions

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

BISON AI

Ask about “How Can a Google Workspace Admin Help a User Locked Out by 2FA? Complete Administrator Guide (2026)”

This interface is ready to connect to your preferred AI provider. No article or user data is sent until that service is configured.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.