How to recover a Google Workspace account without access to the second factor?
The safest route is for another super administrator to validate the user's identity and apply the recovery options available in the console. It is not advisable to disable protection for the entire organization. After regaining access, you should delete lost methods, register new ones, and review recent activity.
Risks to review
- Disable 2SV for all users to resolve an individual case.
- Deliver codes or restore access without validating identity.
- Being left without access due to depending on a single super administrator.
- Keep a phone, key or session active that is no longer under control.
Safe recommendations
- Confirm if there is another super administrator with access to the security settings.
- Validate the user's identity through a known channel before modifying its methods.
- Use backup codes or the administrative recovery procedure when applicable.
- Review and delete the lost device or method after reestablishing access.
- Register at least two suitable methods and provide new backup codes.
- Check activity, forwarding, delegations, and connected applications before closing the incident.
When to seek specialized help
- The affected account is the only super administrator.
- Control of the recovery domain, email or telephone number was also lost.
- There are signs of session theft, rule change, or unauthorized access.
Reference sources
These public sources provide general good-practice guidance. They do not replace an assessment of your environment.

