iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Yes, it can. Multi-factor authentication (MFA) protects the normal sign-in route, but account recovery is a separate process that may let someone regain access after authenticators are lost. To assess your risk, check what evidence recovery accepts, how recovery destinations are changed, and what happens after a reset. The title describes a risk to investigate—not a verified flaw in any particular service.
Why enabled MFA does not settle the recovery question
At sign-in, a service checks credentials and authenticators bound to your account. Recovery is for situations in which you cannot use those authenticators. It may accept recovery codes, a recovery contact, repeated identity proofing, or a risk-based, application-specific process. If recovery succeeds, the service can allow new authenticators to be bound to the account.
That makes recovery a separate route to account access. An MFA prompt at ordinary sign-in does not tell you what evidence is required when all authenticators are unavailable. A password change is not necessarily account recovery: when you can still authenticate with another authenticator already bound to the account, adding a new one is treated as binding an authenticator instead.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsNIST’s current digital identity guidance, SP 800-63B-4, published in July 2025, treats recovery as a distinct event. It is an authoritative benchmark for digital identity systems, not a universal law for every private account; applicable obligations depend on the system and policy. NIST also distinguishes authentication assurance levels (AAL) from identity assurance levels (IAL). NIST publication record · NIST SP 800-63B-4, §4.2
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What happens if you lose your phone with MFA enabled?
The answer depends on the account’s recovery design. A phone may hold an authenticator, receive a code, or serve as a recovery destination; losing it can therefore affect more than one route. Recovery might require an offline code, a code sent to a recovery address, help from a prearranged contact, repeated identity proofing, or another documented process. You need to check the service’s actual instructions rather than assume that losing a phone either locks you out or lets you bypass MFA.
NIST recognizes four general recovery methods:
- Saved recovery codes: Issued in advance for the subscriber to keep.
- Issued recovery codes: Sent to a recovery address. Their validity and minimum entropy depend on the delivery channel.
- Recovery contacts: People designated in advance to participate in recovery.
- Repeated identity proofing: Repeating necessary identity-proofing steps consistent with the original level and checking that the result matches the account.
NIST also allows application-specific processes, such as interaction with an agent, when their use is based on risk analysis and documented. The presence of human support alone does not establish that a recovery flow is insecure. NIST SP 800-63B-4, §4.2.1
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What NIST requires for recovery at maximum AAL2
For an account at maximum AAL2, NIST specifies one of three recovery options. The rule is not that MFA can never be bypassed, and it does not automatically apply to every consumer website.
- Present two recovery codes obtained using different methods.
- Present one recovery code and authenticate with a bound single-factor authenticator.
- Repeat identity proofing, if the account was identity-proofed.
These are alternative evidence combinations in the standard. They are a useful benchmark when reviewing a system that claims maximum AAL2, but they should not be presented as requirements for every service or as proof that a service complies. NIST SP 800-63B-4, §4.2.2.2
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Can someone reset your account without your authenticator?
Possibly, if the service’s recovery process accepts other evidence and that evidence can be obtained or manipulated by an attacker. That possibility is not proof that a particular provider has a vulnerability. For a specific account, the relevant question is what the service accepts when every bound authenticator is unavailable—and whether the evidence is independent of the factors being replaced.
Review the recovery flow for these points:
- Accepted evidence: What must you provide if all authenticators are lost? Is it independent of the devices, phone numbers, or addresses an attacker might already control?
- Recovery destinations: How are recovery addresses and contacts enrolled or changed? What verification protects those changes?
- Notifications and recourse: Does recovery trigger a prompt notification, a waiting period, review, or a way to reverse an unauthorized change?
- Support overrides: Can an agent override normal controls, and what checks and escalation steps govern that decision?
- After recovery: Does the process invalidate lost authenticators, used recovery codes, sessions, and other credentials as appropriate?
- Assurance differences: Does recovery provide evidence comparable to sign-in, or is it a weaker route?
These are evaluation questions, not claims that any named service lacks a control. No particular provider’s recovery flow is assessed here.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Phishing-resistant sign-in does not secure recovery by itself
MFA methods differ in phishing resistance. NIST says manually entered one-time passwords and out-of-band outputs are not phishing-resistant. It identifies WebAuthn, used by FIDO2 authenticators, as an example of phishing resistance through verifier-name binding: the authenticator’s response is tied to the verifier’s domain. NIST SP 800-63B-4: Authenticators
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteA WebAuthn security key or passkey can improve the sign-in authenticator, where the service supports it. It does not automatically strengthen a separate recovery route that might rely on a recovery email, a support interaction, or another method. Check both routes. If you use a physical key, confirm service compatibility and set up a safe recovery plan rather than relying on a single key.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How to make recovery safer before you need it
- Open the account’s security or sign-in settings. Find its official recovery instructions and determine what is accepted when you lose access to every authenticator.
- Secure recovery destinations. Review the recovery email address, phone number, and contacts on file. Remove entries you no longer control, and learn how changes are verified.
- Prepare recovery codes. If offered, save them offline in a secure place. NIST says saved recovery codes must contain at least 64 bits of randomness when this method is supported; a used code must be invalidated and replaced.
- Check alerts and response options. Find out where recovery notifications go and whether you can report or reverse a recovery you did not initiate.
- Review what recovery revokes. Confirm whether the process disables lost authenticators and invalidates sessions or credentials that may be compromised.
- Test your plan without triggering a reset. Read the instructions and confirm that you can reach the recovery destination and locate stored codes. Do not start a recovery flow merely to test it if doing so could lock you out or consume a code.
NIST says recovery must trigger notification to the subscriber or a designee. For saved codes, it also specifies secure offline storage, invalidation after use, and replacement. NIST SP 800-63B-4, §§4.2 and 4.2.1.1
How to compare recovery flows across services
If you are reviewing several accounts, compare them on the same criteria rather than judging by the number of sign-in factors alone:
- Evidence required to recover, and whether it is independent of the factors being replaced.
- How recovery contacts and destinations are enrolled or changed.
- Notifications, waiting periods, review, and reversal options.
- Controls on support-agent overrides.
- Whether recovery revokes or replaces compromised authenticators and sessions.
- Whether recovery offers assurance and phishing resistance comparable to sign-in.
Providers can differ, and a provider-specific conclusion requires checking its current recovery steps, policies, and any relevant plan or account tier. NIST’s threat guidance discusses risks including phishing, social engineering, authentication fatigue, and endpoint compromise; these risks can affect recovery as well as routine authentication. NIST: Threats and Security Considerations
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

