How to Reset 2-Step Verification for a Google Workspace User: Complete Administrator Guide (2026)
Two-Step Verification (2SV), also known as Two-Factor Authentication (2FA), is one of the most important security features in Google Workspace. It protects u...
Two-Step Verification (2SV), also known as Two-Factor Authentication (2FA), is one of the most important security features in Google Workspace. It protects user accounts even if passwords are compromised.
However, there are situations where a user loses access to their authentication method, such as:
- Lost or stolen mobile phone
- Factory reset of smartphone
- Broken security key
- Deleted Google Authenticator app
- New phone without transferred authentication data
- Lost backup codes
- Unable to receive Google Prompts
In such cases, a Google Workspace Administrator can reset the user's 2-Step Verification, allowing them to enroll again with a new authentication method.
This article explains everything administrators need to know about resetting 2-Step Verification safely and securely.
What Does Resetting 2-Step Verification Mean?
Resetting 2-Step Verification does not disable security permanently.
Instead, it removes the user's currently registered second-factor authentication methods, including:
- Google Authenticator codes
- Google Prompt registrations
- Security Keys (FIDO/U2F)
- Backup codes
- Registered verification devices
- Passkeys (where applicable)
The user's password remains unchanged.
After the reset, the user must complete the enrollment process again.
When Should an Administrator Reset 2-Step Verification?
A reset should only be performed when the user cannot access their second factor.
Common scenarios include:
- Lost mobile phone
- New phone without migrated Authenticator
- Deleted Authenticator application
- Broken hardware security key
- Phone stolen
- Unable to receive verification prompts
- Employee returned after long absence
- Verification methods accidentally removed
Situations Where Reset Is NOT Required
Resetting is unnecessary if the user still has access to:
- Backup codes
- Another registered device
- Google Prompt on another phone
- Secondary security key
- Passkey
- Alternate verification option
Users should first try these recovery methods before contacting the administrator.
Who Can Reset 2-Step Verification?
Only administrators with appropriate privileges can perform the reset.
Typically:
- Super Admin
- User Management Admin (with required permissions)
- Custom Admin Roles with 2SV management rights
Standard users cannot reset another user's authentication methods.
Before Resetting 2-Step Verification
Administrators should verify the user's identity.
Recommended verification methods:
- Government ID
- HR confirmation
- Manager approval
- Internal helpdesk ticket
- Employee ID verification
- Video verification (for remote employees)
Never reset authentication without confirming identity.
How to Reset 2-Step Verification
Step 1
Sign in to the Google Admin Console
https://admin.google.com
Step 2
Navigate to:
Directory
↓
Users
Step 3
Select the affected user.
Step 4
Open the user's security information.
Depending on the Admin Console version, navigate to:
Security
or
User Information
→ Security
Step 5
Locate:
2-Step Verification
Step 6
Click:
Reset 2-Step Verification
or
Clear Verification Methods
(depending on the Admin Console interface)
Step 7
Confirm the reset.
Google will remove all registered verification methods.
Step 8
Inform the user to sign in again.
After entering the password, Google will ask them to configure new authentication methods.
What Happens After Reset?
The user will:
- Sign in with username and password
- Be asked to enroll in 2-Step Verification again
- Register a new phone
- Create new backup codes
- Register new security keys if required
- Reconfigure Google Authenticator
The previous verification methods become invalid immediately.
Does Reset Disable 2-Step Verification?
No.
If your organization enforces mandatory 2-Step Verification:
- The user must enroll again
- They cannot bypass the policy
- Access remains protected
The reset only clears existing authentication methods.
What Gets Removed?
A reset typically removes:
- Google Authenticator
- Google Prompt
- Backup Codes
- Security Keys
- Trusted Devices
- Passkeys
- Phone registrations
The password remains unchanged.
What Does NOT Change?
Resetting does not:
- Change the password
- Delete Gmail
- Remove Drive files
- Remove Calendar data
- Delete Workspace account
- Remove licenses
- Change email address
User Experience After Reset
The user signs in:
Email
↓
Password
↓
2-Step Verification required
↓
No registered device found
↓
Start setup
↓
Choose authentication method
↓
Complete enrollment
↓
Account access restored
Recommended Authentication Methods
Google recommends using:
Google Prompt
Best for most users.
Advantages:
- Easy
- Secure
- Push notification
- Resistant to phishing
Passkeys
Excellent security with:
- Fingerprint
- Face unlock
- Device PIN
Security Keys
Best for administrators.
Examples:
- Titan Security Key
- YubiKey
Google Authenticator
Still widely used.
Works offline.
Should Backup Codes Be Generated Again?
Yes.
Old backup codes become invalid after the reset.
Users should:
- Generate new backup codes
- Print securely
- Store offline
- Never share them
Best Practices for Administrators
✔ Verify user identity
✔ Reset only when necessary
✔ Encourage Google Prompt
✔ Recommend Passkeys
✔ Require backup codes
✔ Ask users to register two devices
✔ Encourage security keys for administrators
✔ Review login activity after recovery
Security Considerations
Resetting 2-Step Verification is a sensitive administrative action.
Potential risks include:
- Social engineering
- Impersonation attacks
- Insider threats
- Unauthorized account recovery
Always follow documented identity verification procedures before approving a reset.
Common Mistakes
Resetting before verifying identity
Very risky.
Forgetting backup codes
Always advise users to generate new ones.
Not registering multiple methods
Users should configure:
- Google Prompt
- Backup Codes
- Security Key
instead of relying on only one device.
Using only SMS verification
SMS is less secure than Google Prompt or Passkeys.
Troubleshooting
User still cannot sign in
Verify:
- Correct password
- Account is active
- 2-Step Verification policy
- Internet connectivity
- Correct time on mobile device
Reset option not visible
Possible reasons:
- Insufficient admin privileges
- Wrong admin role
- Admin Console permission restrictions
User immediately prompted again
This is expected.
If 2SV enforcement is enabled, Google requires new enrollment after the reset.
User lost phone and password
Recover the password first.
After password recovery, reset 2-Step Verification if needed.
Frequently Asked Questions (FAQ)
Q1. Can a Google Workspace administrator reset 2-Step Verification?
Yes. Administrators with the required permissions can reset a user's registered verification methods.
Q2. Does resetting 2-Step Verification change the user's password?
No. The password remains unchanged.
Q3. Will Gmail or Drive data be deleted?
No. Resetting only removes registered authentication methods.
Q4. Can the old phone still approve logins?
No. Once reset, previously registered devices and verification methods become invalid.
Q5. Does the user need to enroll again?
Yes. The user must configure new verification methods after the reset.
Q6. Can administrators reset their own 2-Step Verification?
Yes, provided they have sufficient administrative permissions. Organizations should ensure multiple Super Admins are available to avoid lockout scenarios.
Q7. Is SMS verification recommended?
Google generally recommends stronger methods such as Google Prompt, Passkeys, or Security Keys over SMS because they provide better protection against phishing and SIM-swap attacks.
Q8. Can backup codes still be used after a reset?
No. Existing backup codes are invalidated, and the user should generate a new set after re-enrolling.
Q9. Can administrators see a user's verification codes?
No. Administrators cannot view or recover a user's one-time verification codes or secret keys.
Q10. Is resetting 2-Step Verification logged?
Yes. Administrative actions, including security-related changes like resetting 2-Step Verification, are recorded in Google Workspace audit logs for organizations with the appropriate reporting features.
Conclusion
Resetting 2-Step Verification is a secure recovery mechanism that helps users regain access to their Google Workspace accounts after losing access to their authentication methods. While the process is straightforward for administrators, it should always be performed only after verifying the user's identity. After the reset, users should promptly enroll with stronger authentication methods such as Google Prompt, Passkeys, or Security Keys and generate new backup codes to maintain a high level of account security. Following proper administrative procedures ensures both account recovery and continued protection against unauthorized access.
#GoogleWorkspace #GoogleAdmin #WorkspaceAdmin #TwoStepVerification #2StepVerification #2FA #MFA #GoogleAuthenticator #GooglePrompt #Passkeys #SecurityKey #CyberSecurity #CloudSecurity #IdentityManagement #AccountRecovery #WorkspaceSecurity #GoogleSecurity #ITAdministrator #SystemAdministrator #ITSupport #GoogleCloud #AdminConsole #GoogleWorkspaceSupport #Authentication #UserManagement #SecureLogin #ZeroTrust #BusinessSecurity #EnterpriseIT #CloudComputing #GoogleTips #WorkspaceTips #PasswordSecurity #BackupCodes #PhishingProtection #AccessManagement #AuthenticationSecurity #GoogleHelp #WorkspaceGuide #ITPro #NetworkSecurity #BusinessIT #TechSupport #CyberAwareness #WorkspaceManagement #DigitalSecurity #GoogleWorkspaceAdmin #SecurityBestPractices #CloudAdmin #AdminGuide
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.