SecurityHow Long
How Long Account Recovery Takes When You Lose Two-Factor Access
Provider-by-provider expectations and the backup measures worth setting up beforehand

On this page
- How Long it Takes to Get Your Account Back When You Lose Two-Factor Access
- Apple: The Longest Published Wait
- Google: Risk-Based Delays, Not a Fixed Timer
- GitHub: A Short, Explicit Business-Day Window
- Microsoft: 24-Hour Lockout Versus 30-Day Recovery Path
- What Proof Shortens the Delay
- Proactive Preparation to Shorten Delayed Recovery
- Sources
How Long it Takes to Get Your Account Back When You Lose Two-Factor Access
How long will you be locked out of an account if you lose access to two-factor authentication (2FA)? The answer is: It depends. Major providers today use different waiting periods, different proof standards, and different ways to let you regain access more quickly. This guide describes the specific account-recovery process at four major providers, based on their latest published guidance. It also summarizes the fastest shortcuts that might let you regain access within hours instead of days, and recommends the backup measures you should have already set up to avoid those delays in the first place.
Apple: The Longest Published Wait
If you're locked out of an Apple account with 2FA, the process can take "several days or longer," with no possibility of shortening the wait by contacting Apple support. Apple does confirm the user's request by email and commits to a date and time when the account can be accessed again, but that confirmation may take up to 72 hours to arrive.
In some cases, Apple will send a six-digit code to the primary email address to let the user authenticate more quickly, but Apple does not commit by when or whether that path will be available. Additionally, Apple may verify the person's identity using a historic credit card that they continue to control, but Apple does not publish any criteria for when this is the faster option. Separately, Apple Community documentation recommends waiting at least 24 hours at iforgot.apple.com before checking again.
Google: Risk-Based Delays, Not a Fixed Timer
Google recovery times can be either fast or very slow, depending on indications of account risk. Recovery waits might be as short as a few hours, or may take "a number of days," sometimes without any estimate. If the account recovery is delayed, Google support suggests trying the process again after 48 or 72 hours, from a familiar device and location. Turning on the recovery shortcut for "trusted devices" might help commit more locations and devices to a white list.
Like Apple, Google also supports 2FA checkpoints with a proprietary recovery code, but unlike Apple, Google does not offer a step-by-step guide on their help website placing recovery codes in a specific position in the recovery process. Google last year introduced support for passwordless authentication, adding the option to verify from a trusted device or screen in recovery, but as of 2024, Google reports varying adoption rates across platforms.
GitHub: A Short, Explicit Business-Day Window
When GitHub 2FA is inactivated, ) publishes the shortest published recovery clock: regaining access, once the authentication process is complete, takes "up to three business days." Decentralized checkpoints are further complicated - GitHub notes, "We may not be able to review additional requests sent on your behalf during the 3 business day wait" — though GitHub declines comment whether the clock begins at a specific point. GitHub does not provide specific comment about the prevalence of shortcuts here, but as an enterprise-oriented site, notes that it attempts to integrate with existing multi-factor authentication. Recovery-code support may open that door, but GitHub custom-shortens that link in HTML, though not the original or Microsoft equivalents.
Microsoft: 24-Hour Lockout Versus 30-Day Recovery Path
Microsoft documentation outlines both recovery type and locking times. If too many failed sign-in attempts are made, Microsoft imposes a sign-in lockout of about 24 hours. If the account password is reset from a lost 2FA source, Microsoft's documentation posted in 2024 says, "it may take up to 30 days for you to update your security information and recover access to your account." During that 30-day period, the account will not be accessible to sign in to sites or services.
Microsoft documentation says account owners can shorten this delay with an email link and other proofs, similar to Apple or Google, if the account owner can prove access before the 30-day segment completes. Microsoft supports a wide range of recovery codes and initiating 2FA using proprietary usability tools, but, unlike at Apple, authentication once the account owner has access to their account is overall displayed mainly in Q&A touchpoints. Microsoft strongly recommends against storing recovery codes in the cloud.
What Proof Shortens the Delay
If you're choosing a provider with the shortest recovery waits, look for verified reports of faster authentication services like those above. If you've already lost 2FA access, your best bet for avoiding a multi-day wait is to be able authenticate again with one of these credential sources:
- A recovery code, if 2FA was previously set up, including proprietary tools in Microsoft, Google, and even decentralized cloud services.
- A six-digit email code, which Apple says could be available, but does not specify when.
- A trusted device or trusted location, Google says this might lower the wait, but recovery-code support could remove delays in Microsoft and decentralized cloud services.
- Payment-card verification, which Apple says could work, but doesn't commit when, and does not specify a default window.
- Evidence of past log-ins, correspondences, or phone numbers from the targeted location.
Proactive Preparation to Shorten Delayed Recovery
While Apple, Google, Microsoft, and GitHub all describe delays ranging from 24 hours to 30 days, the availability of a recovery code or other emergency checkpoints often mean that pages could authenticate in the equivalent of an hour. Given the 24-hour wait on the fastest recovery codes, recovery-code support should be an enterprise priority.
2FA proprietary tools are also central, but these are not individually supported across platforms. To prepare for a fast recovery, finish the 2FA setup, though not with codes stored in a cloud location, but connected to location, device and card checkpoints to hasten an otherwise long recovery time.
Sources
- Apple Support — support.apple.com
- Apple Community documentation quoting Apple guidance — discussions.apple.com
- Google Account Help — support.google.com
- GitHub documentation in GitHub Docs repository — github.com
- Microsoft Q&A — learn.microsoft.com


