Locked Out by 2FA? Why Microsoft and Google Keep Asking — and How to Get Back In
September 20, 2026
You still have your phone, you still know your password, and it still will not let you in. Here is what each of those screens is actually doing — and the one move that turns ten bad minutes into a bad week.
If it feels like Google and Microsoft ask you to "verify it's you" far more than they used to, you're right — and in 2026 there is a second thing going on underneath it. Both companies are actively retiring the text-message code. That means the screen you get today is often not the screen you got last year, on the same computer, with the same account. Add a new device, a new location, a VPN, or simply a long gap since your last sign-in, and something will ask you to prove yourself. It's good security. It's also the single most common reason people get locked out of their own email.
This article is about the ordinary version of that problem: you still have your phone, you still know your password, and the sign-in screen will not let you through anyway. If you have lost everything at once — the phone and the computer in the same fire or flood — that is a harder and quite different job, and we wrote it up separately.
Why it changed: both companies are retiring the text-message code
This is not a rumour or a tech-press prediction. Microsoft publishes a support page titled "Microsoft to stop sending SMS codes for personal accounts," and its first line is plain: "Microsoft is committed to advancing security standards and as such, we will start phasing out SMS as a method of authentication and account recovery for personal Microsoft accounts." The reason it gives is blunter still — "SMS-based authentication is now a leading source of fraud" — and the replacement it names is a passkey plus what it calls a verified email.
One honest caveat, because it changes what you should do about it: that page gives no cutoff date. There is no deadline to write on the calendar. The change arrives on your account when it arrives, which is exactly why it catches people — nothing announced itself, the sign-in screen just started behaving differently one Tuesday.
Google is walking the same road from the other side. Its own 2-Step Verification page recommends its push prompt over codes, and it now says outright: "In certain cases, Google will require that you scan a QR code with your mobile device to verify." Not "may offer" — require. If you have ever had a sign-in screen show you a square of black-and-white dots instead of texting you six digits, that was not a glitch.
The practical consequence is worth saying in one sentence, because everything below follows from it: your phone number is no longer a reliable key to your own accounts, and if it is the only thing standing between you and your email, you are one dead handset away from a very long week.
What the sign-in screen can ask you for now
There are six things you may be asked for, and most people have met three of them. A passkey — your fingerprint, your face, or the PIN that unlocks the device itself. A push prompt, which on Google arrives on an Android phone signed in to the account or an iPhone running the Gmail app, and shows you the device and location doing the asking so you can allow or block it. A six-digit code from an authenticator app. A code by text or voice call. A QR code to scan. Or a backup code from the set of 8-digit codes Google lets you print in advance.
Which one you get is not your choice, and that surprises people more than anything else on this list. Google says so in its own words: "The challenge you'll get is what Google thinks is best to help you sign in easily and keep out hijackers." The screen is making a risk judgement about this particular attempt, on this particular machine, and handing you the challenge it trusts for it.
One clarification that saves real time, because we see it on house calls: the Microsoft Authenticator app only pushes approvals for Microsoft accounts. Microsoft's own FAQ says "Notifications won't work for third-party accounts, like Google or Facebook." If you are staring at your phone waiting for an Authenticator prompt so you can get into Gmail, you are waiting for something that is never going to arrive — Google's prompt comes through the Gmail app or an Android phone, not through Microsoft's app.
The code arrived, you typed it, and the screen says it is wrong
Start with the one that accounts for more failed sign-ins than any other, and which almost nobody knows. Google states it directly: "If you requested multiple verification codes, only the newest one works." Picture what everyone actually does. The text is slow, so you tap "resend." Then the first one lands, you type it, and it is refused — because by requesting a second code you killed the first. Tap resend twice and the two codes now sitting on your phone are both dead. Always type the most recent message, and once you have pressed resend, ignore everything above it.
The next-commonest is the clock. An authenticator app code rotates every thirty seconds — Microsoft explains that countdown ring as exactly that — so a code you started typing at second twenty-nine is wrong by the time you press enter. If the ring is nearly empty, wait for the next one rather than racing it. The same applies, more loosely, to texted codes typed twenty minutes after they landed.
Then there is the case where the code is fine and you are looking at the wrong mailbox or the wrong phone. To protect you, Microsoft hides where it is sending things: "we only show you the last two digits of your phone number or the first two characters of your email address." Two digits is not much to recognise a number by. People routinely read "•••••••27" as the phone in their hand when it is actually the number they gave up in 2019, or as their main email when it is an old address they have not opened in years.
And one thing worth knowing so you can tell a real code from a fake one, since this is precisely where scams live. Microsoft's texts come from the shortcode 69525 or from "Microsoft" — "Microsoft uses 69525 to send security verification codes and alerts related to account activity" — and it notes that if a genuine message includes a link, "we will also include part of your account email address to help you know it's genuine." Emailed codes come from an @accountprotection.microsoft.com address, so if nothing has arrived, look in the junk folder before assuming it was never sent. Google, for its part, says this and means it: "You won't receive a call from Google to verify a code." Nobody legitimate will ever phone you and ask you to read a verification code out loud.
No code arrives at all
Sometimes the code genuinely is not coming, and there are four ordinary reasons that have nothing to do with your phone being broken.
The first is that the system decided not to send it. Google puts it this way: "If we notice something different about how you sign in, like your location, you might not be able to get a verification code through text message." Sign in from a hotel, a new ISP, a work laptop or with a VPN switched on, and the text route can simply close — not as a fault, as a decision. Turning the VPN off and trying from the machine you normally use is a real fix, not a superstition.
The second catches a specific and growing group of our customers: anyone whose home phone is internet-based. Microsoft will not accept those numbers at all — "VOIP numbers cannot be added as a way to sign in or get verification codes. Please add a mobile phone number." If you dropped the copper line for an Ooma, MagicJack or similar box, that number cannot be your account's lifeline. Google flags the sharper version of the same trap, which is circular in a way that is genuinely difficult to get out of: "If you use Google Voice to get verification codes, you could lock yourself out of your account." The code to get into your Google account gets delivered to a service that needs your Google account.
The third is that it went where you told it to go, long ago. Microsoft texts only the primary phone number on the account, and emails codes only to your primary alias or an address you specifically added as a way to verify sign-in. If neither of those is somewhere you can read today, no amount of pressing resend will help.
The fourth is the old phone in the drawer, and it is the one that makes people think the app is broken. Microsoft's Authenticator FAQ explains that when you are waiting on an approval, "a push notification is sent to the device where the Authenticator app was last used." If your previous handset still has the app installed and it is sitting in a kitchen drawer, powered off or on the wi-fi, that is where the prompt has gone. Take the app off old phones when you replace them.
The move that turns ten bad minutes into a bad week
Here is the most useful paragraph in this article, and it is the opposite of what instinct tells you to do. When the codes are not working, the natural response is to try again, and again, from a couple of different methods, quickly. That is the thing that locks the account.
Microsoft is unusually candid about it. Excessive or repetitive requests, it says, "can result in temporary or permanent blocks" — and on how to get out of one: "Sometimes waiting a day can be enough to remove a block. Don't make lots of repeated attempts, as this may reset any time lock." Read that last clause twice. The timer you are waiting out gets restarted by the attempts you make while waiting. Microsoft's advice if a day is not enough is to wait longer, as much as a week.
This also explains an error message that reads like a broken feature and is not one. "Try another verification method" is usually a block, not a comment on the method you chose — the same page lists it under blocks caused by unusual activity and high request volume. Switching to a different method on the account, or to a different network, is the documented way through it; hammering the same button is not.
Google's equivalent is a queue rather than a lock. If you have lost your second step entirely and have to go through full account recovery, it warns that "it can take 3-5 business days for Google to make sure it's you." Not hours. Days.
So when it stops working, stop. Write down which verification methods the account actually has on it, work out which of them you can still reach today, and try that one — tomorrow if necessary, from the computer and the internet connection you normally use. Patience is not a personality trait here; it is the technique.
The number you added last week does not work yet — and the clock that quietly deletes it
A new phone number is not live the moment you add it. Google allows up to seven days before it will lean on a newly added number, and the same waiting period applies to other recovery factors. If you are mid-crisis, adding a number today and expecting it to rescue you today does not work — we cover that set of delays in detail in the article about losing everything at once.
What is less known, and what we think is the single most useful thing on this page for anyone who has already been through a lockout, is what happens to a method Google is suspicious of. Its own page on at-risk sign-in methods says that if it suspects a method "may have been added without your permission," it restricts that method and emails you a security alert — and then: "If you take no action to verify the at-risk method, Google automatically removes it after 30 days." The 2-Step Verification page describes the same thing for phone numbers specifically: a number that looks suspicious gets disabled, you get thirty days to confirm you added it, and after that it is deleted.
Now the sting, and it is the reason we have started setting passkeys up for customers as routine rather than as a nicety. To rescue a restricted method — or to skip the seven-day wait on a new one — Google requires an extra check, and only one kind of key opens that door: "You must have a trusted passkey or security key to re-enable an at-risk sign-in method." If you do not have one, there is no fast lane and no override. A passkey is not just a quicker way to sign in. It is the only thing that lets you fix the other methods when they are the ones in trouble.
Microsoft has its own version of a thirty-day wall, and it is triggered by a well-meaning tidy-up. Replace all of your security info in one go and, in Microsoft's words, "you must wait 30 days before being able to sign in." There is a partial escape with a catch worth understanding: "If you find your current security info during those 30 days, you can still use it to sign in but doing so will cancel the update to your security info." The rule that follows is simple and worth obeying without exception — change security info one item at a time, and never remove the last method that still works.
One more Microsoft prompt that people click past for weeks and then get caught by: the "make sure you can receive a security code" nag. It is not decorative. "You can skip it for 24 hours at a time, but after seven days from the first notice you'll have to verify or add new security info before you can sign in again." Seven days of snoozing and the door closes. Deal with it the first time you see it, when you are calm and signed in, instead of on the morning you need the account.
Codes and approval prompts you never asked for
A verification code arriving out of nowhere is alarming, and the alarm is mostly misplaced. Microsoft lists three causes: someone is trying to get into your account, someone mistyped their own phone number or email and it happens to be yours, or a code you requested earlier was simply delayed. Its instruction is one line and it is the whole answer: "Do not respond to any codes that you did not request. If someone is trying to access your account, without the code, your account is safe."
The same goes for a push prompt you did not trigger. Google's prompt shows you the device and the location attempting the sign-in precisely so you can look at it and block it. Deny it. What you must never do is approve one to make it stop — a stranger with your password and nothing else is stuck forever, and a single tap of "Yes" hands them everything.
If unrequested codes keep coming, that is a signal rather than an emergency: someone has your email address and is trying it, which usually means the address turned up in a breach. Change the password to something not used anywhere else, then look at the account's own activity page — account.live.com/activity for Microsoft, the security section of myaccount.google.com for Google — to confirm nobody actually got in.
And the version that costs people real money: the call that follows. Someone rings, says they are from Microsoft or Google or your bank, explains that they are "verifying" the suspicious activity you have just seen, and asks you to read them the code that just arrived. The code is the only thing they are missing. Nobody legitimate will ever ask for it.
Why the screen looks different every time you sign in
It is worth knowing that the inconsistency is deliberate, because "it never used to ask me this" sends a lot of people down the wrong path entirely.
Google adapts the sign-in screen to you. Create a passkey and it quietly changes your default: "By default, when you create a passkey you opt in to a passkey-first, password-less sign in experience" — which you can switch back in your account settings if you would rather be asked for the password first. And it learns from how you behave. In its own words: "If you choose 'Try another way' often, Google will offer the passkey challenge less frequently in the future to reflect your implied preferences." Click past the fingerprint prompt enough times and it stops offering it, which is fine until the day it was the option you needed.
There is also a mechanical reason a passkey can vanish from the menu: if the screen lock on the device holding it has been turned off, that passkey cannot be used until the screen lock is back on. People switch off a PIN because it is annoying and lose a sign-in method without connecting the two events.
The takeaway is not to fight it. It is that "the way I always sign in" is not a thing you can rely on, so an account needs more than one way in that you can actually reach.
How to reset your password
Google: go to accounts.google.com, choose "Forgot password," and follow the prompts — ideally on a phone or computer already signed into the account, which dramatically improves your odds.
Microsoft / Outlook / Hotmail: go to account.live.com/password/reset and work through the identity checks. Microsoft may ask for security-info codes and, if those fail, an account recovery form at account.live.com/acsr where you answer questions only the real owner should know.
Either way, if the first method stalls, look for the "Try another way" link and work down the options — persistence from the right device usually wins. And do it from a device, browser and location you have used with that account before: familiar context is the strongest signal either company has that you are you, and it is free.
Why this is especially hard for older folks
For people who didn't grow up with this — and who may already find a keyboard, mouse, or touchscreen tricky — these verification gauntlets can be genuinely overwhelming. Codes expire in seconds, you're bounced between your phone and your computer, the text is tiny, and you're asked to install an app in the middle of signing in. It's no wonder a simple "just check your email" turns into hours of frustration and, too often, getting locked out of an account you've had for years.
A big part of our work — especially across the desert and retirement communities we serve — is sitting down with someone, patiently, and getting them back into their accounts without the panic. We don't rush, we explain each step in plain language, and we set things up afterward (a trusted device, a passkey, fewer prompts) so it's far less likely to happen again. If this is you or a parent, that's exactly the kind of call we like.
Set yourself up so it doesn't happen again
Twenty minutes on a calm afternoon, signed in, with everything working. That is the whole job, and it is the difference between a lockout being an inconvenience and a lockout being a fortnight.
Make sure the account has at least two live methods, and that at least one of them is not a phone number — that is the whole point of everything above. Add a passkey on the device you actually use every day, and do it for the unglamorous reason rather than the marketing one: a trusted passkey is the only key that lets you re-enable a restricted method or skip the seven-day wait later. Print Google's backup codes and put them somewhere that is not your phone and not your inbox — a drawer at home is genuinely fine, because a code on paper cannot be phished, SIM-swapped or left in a taxi.
Then go through the list of methods already on the account and check each one is something you can reach today. Old numbers, a work address from two jobs ago, an alias nobody opens: remove them, but remove them one at a time and never all in one sitting, because on a Microsoft account replacing everything at once starts a thirty-day wait. Do not use an internet phone line or a Google Voice number as a verification number. And when you sign in on your own computer, tick "Don't ask again on this computer" — only ever on a machine you own and nobody else uses.
If you're stuck in a verification loop right now, or you just want this set up so it protects you without locking you out, we do this all the time. We come to you, we don't rush, and we leave the account with two ways in that you can actually reach — plus a written note of what they are, which is the part people are most grateful for six months later.
Keep reading
- What Is a Passkey — and What Happens If You Lose the Phone It Is Saved On?
- Lost Your Phone and Laptop in a Fire? Getting Back Into Your Accounts When Every Backup Was in the Same Building
- Your Password "Appeared in a Data Leak": What That Warning Means and What to Do
- You Got an Email From Your Own Address? How to Tell Spoofing From an Actual Hack
- You Went Looking for Them: Fake Bill-Pay Sites and Fake Support Numbers in Your Own Search Results
Free calculators
Service areas we cover
We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.
Call (626) 655-0020