Locked Out: MFA Code Not Working and You Can't Sign In
This runbook is for customers who can’t sign in because their multi-factor authentication (MFA) code is being rejected or they no longer have access to the second factor. It walks you through the fastest checks first, then the safe recovery options, and shows when you need your provider’s support team to reset MFA.
TL;DR — If your MFA code is failing, the most common cause is a time mismatch on your phone or computer, or you’re using the wrong MFA method (authenticator app vs SMS vs backup code). Start by checking your device time is set to automatic, then try a backup code or another enrolled method; if you no longer have the device, use the account recovery flow or contact support for an MFA reset. Reading time: ~6 min
The scenario
It’s a normal Tuesday afternoon and you open the app to approve a client change, but the sign-in screen keeps rejecting your MFA code. You’ve already reset your password once, so you know the password is right, but the login page still says the verification code is invalid. Your old phone was replaced last week, or maybe you’re traveling and your SMS messages are delayed, and now you’re stuck outside your own account. You need the fastest path back in without making the lockout worse.
Symptoms
- You can enter your username/email and password, but the next step fails.
- The login page shows messages like:
Invalid verification codeIncorrect code. Try again.The code you entered has expiredToo many attempts. Please try again laterWe couldn't verify it's you
- Your authenticator app (an app that generates 6-digit login codes) shows a code, but the site rejects it.
- SMS codes arrive late, never arrive, or arrive after the page says they expired.
- Push approval notifications do not appear on your phone.
- Backup codes are missing, already used, or also rejected.
- After several tries, your account is temporarily locked or rate-limited (blocked for too many attempts).
Likely causes
| Cause | How common | Quick check |
|---|---|---|
| Device time is wrong, so time-based MFA codes are out of sync | Very common | On your phone: Settings → Date & Time → turn on Set Automatically |
| You are using the wrong MFA method or wrong account entry in the authenticator app | Very common | On the sign-in page, click Try another method |
| You replaced/lost the enrolled phone or authenticator app was not transferred | Common | Try your saved backup code on the MFA screen |
| SMS or email delivery is delayed, blocked, or going to the wrong number/address | Common | On the MFA screen, click Resend code once and compare the last 2-4 digits/email shown |
| The account is temporarily locked after too many failed attempts | Common | Wait for the exact lockout period shown, then try again once |
| Browser/session issue, cached login state, or VPN/proxy is interfering | Occasional | Open a private/incognito window and sign in there |
| Your account needs a manual MFA reset by support/admin | Less common | Use the Can't access your device? or Account recovery link on the sign-in page |
Step-by-step diagnosis
-
Check whether your device time is automatic
- Phone path:
Settings → Date & Time → Set Automatically(Android wording varies slightly) orSettings → General → Date & Time → Set Automaticallyon iPhone. - Computer path: turn on automatic date/time in your system settings.
- This is your problem if: after turning on automatic time, the next authenticator code works within 30 seconds.
- Jump to:
### Device time is wrong, so time-based MFA codes are out of sync
- Phone path:
-
Confirm you are using the same MFA method the site expects
- On the sign-in page, click
Try another method,Use a different method, or similar wording. - Compare the options shown: authenticator app, SMS, email code, security key, backup code.
- This is your problem if: the page expects SMS but you were entering an authenticator-app code, or you have multiple entries for the same service in your app and one works while the other fails.
- Jump to:
### You are using the wrong MFA method or wrong account entry in the authenticator app
- On the sign-in page, click
-
Try a backup code before doing recovery
- On the MFA prompt, click
Use backup codeorEnter a recovery code. - Enter one unused backup code exactly as saved, including dashes if shown.
- This is your problem if: the backup code works and gets you in immediately.
- Jump to:
### You replaced/lost the enrolled phone or authenticator app was not transferred
- On the MFA prompt, click
-
Check whether the code is being delivered to the right place
- On the MFA page, click
Resend codeonce. - Verify the masked destination shown, such as
***-***-12orj***@example.com. - This is your problem if: the destination is an old phone number/email, or the message arrives too late to use.
- Jump to:
### SMS or email delivery is delayed, blocked, or going to the wrong number/address
- On the MFA page, click
-
Rule out a browser/session problem
- Open a private/incognito window and sign in again.
- If you use a VPN (a service that routes traffic through another network), turn it off for one test.
- This is your problem if: the same account and code work in private browsing or with the VPN/proxy disabled.
- Jump to:
### Browser/session issue, cached login state, or VPN/proxy is interfering
-
Check whether you are rate-limited or temporarily locked
- Read the exact message on screen. If it says to wait 15 minutes, 30 minutes, or similar, stop trying until that time passes.
- This is your problem if: every code is rejected immediately after many attempts, and the page shows a timeout or lockout message.
- Jump to:
### The account is temporarily locked after too many failed attempts
-
Use the built-in recovery flow
- On the sign-in page, click
Can't access your device?,Lost your phone?,Trouble signing in?, orAccount recovery. - Follow the identity checks exactly as prompted.
- This is your problem if: you no longer have any working second factor and recovery offers identity verification or support contact.
- Jump to:
### Your account needs a manual MFA reset by support/admin
- On the sign-in page, click
Fixes
Device time is wrong, so time-based MFA codes are out of sync
Time-based one-time passwords (TOTP, a 6-digit code that changes every 30 seconds) fail if your phone or computer clock is off.
- On iPhone:
Settings → General → Date & Time → Set Automatically - On Android:
Settings → System → Date & time → Set time automaticallyandSet time zone automatically - Then close and reopen the authenticator app.
- Wait for a fresh code to appear and enter the new 6-digit code before it expires.
If your authenticator app has a time correction option, use it if available. Wording varies by app, so use the app’s settings/search for time correction or sync time.
Verify it worked: the next newly generated code is accepted on the first try.
You are using the wrong MFA method or wrong account entry in the authenticator app
It is common to have multiple entries for the same service, especially after re-enrolling MFA.
- On the sign-in page, click
Try another method. - Choose the method you actually enrolled:
Authenticator appText message / SMSEmail codeSecurity keyBackup code
- If your authenticator app shows two entries with the same service name, try the most recently added one.
- If you recently scanned a new QR code during setup, old entries usually stop working. Use the newest entry only.
Verify it worked: one method consistently gets you past the MFA screen, and you can then remove old/duplicate MFA entries from your account security settings.
You replaced/lost the enrolled phone or authenticator app was not transferred
If you changed phones, the authenticator app may not have moved with your accounts unless you explicitly transferred or restored it.
- On the MFA screen, click
Use backup code. - Enter one unused backup code.
- After you sign in, go to your account security page in the provider’s dashboard, usually something like
Profile/Avatar → SecurityorAccount Settings → Security. - Remove the lost device from MFA methods.
- Enroll a new authenticator app by clicking
Set up authenticator apporAdd MFA method, then scan the QR code. - Generate new backup codes and save them in a password manager (an app that stores secure notes and passwords).
⚠️ If you no longer have the old phone and do not have backup codes, do not keep guessing codes. Repeated failures can extend the lockout and slow down recovery.
Verify it worked: the new phone generates a code that is accepted, and the old device no longer appears in your security settings.
SMS or email delivery is delayed, blocked, or going to the wrong number/address
SMS and email are more fragile than authenticator apps, especially when traveling, roaming, or using spam filtering.
- On the sign-in page, click
Resend codeonce. - Confirm the masked phone number or email belongs to you.
- If it is wrong, use another method or account recovery; you usually cannot fix the destination until after signing in.
- If the destination is correct but delivery is slow:
- Wait for the newest code only; older codes are often invalidated when you resend.
- Turn off Focus/Do Not Disturb if push/email alerts are hidden.
- Check spam/junk if using email codes.
- If traveling, switch from SMS to authenticator app or backup code if available.
Verify it worked: the most recently sent code arrives promptly and is accepted before expiry.
The account is temporarily locked after too many failed attempts
This is a safety control to slow down guessing.
- Stop entering codes until the exact wait period shown on screen has passed.
- Do not click
Resend coderepeatedly during the lockout unless the page explicitly tells you to. - After the wait period, try exactly once using:
- a freshly generated authenticator code, or
- a backup code, or
- a different enrolled method.
If the page does not show a timer, wait at least 15-30 minutes before trying again.
Verify it worked: the lockout message disappears and a valid code is accepted on the first post-wait attempt.
Browser/session issue, cached login state, or VPN/proxy is interfering
Old cookies (saved browser login data), blocked scripts, or unusual network routes can break MFA challenges.
- Open a private/incognito window and retry sign-in.
- If that works, clear cookies/site data for the affected site in your browser settings, then sign in normally.
- Temporarily disable browser extensions that block scripts or privacy popups.
- Turn off your VPN/proxy for one sign-in attempt.
- If you are on a work-managed device, try another trusted browser on the same device.
Verify it worked: sign-in succeeds in private browsing or after clearing site data, and continues to work in a normal window afterward.
Your account needs a manual MFA reset by support/admin
If you have no working second factor and no backup codes, recovery usually requires identity verification by the provider or your organization’s admin.
- On the sign-in page, click
Can't access your device?,Trouble signing in?, orAccount recovery. - Complete the prompts exactly.
- If recovery sends you to support, include:
- your account email/username
- the last successful sign-in date if you know it
- whether you changed phones/numbers recently
- which MFA methods you used before
- a screenshot of the exact error message
- If this is a company-managed account, contact your internal admin first; they may be the only party allowed to reset MFA.
Use a short template like this:
Subject: MFA reset request for locked account
I am locked out of my account because my MFA method is no longer working.
Account email: you@example.com
Last successful login: 2026-08-01 (approx.)
Issue: Authenticator/SMS code is rejected or I no longer have access to the enrolled device.
I have already tried automatic time sync, backup codes, another browser, and the recovery link.
Please advise on the identity verification steps required for an MFA reset.
Verify it worked: support/admin confirms the reset, and you can sign in and enroll a new MFA method.
Prevention
- Store backup codes in a password manager secure note
- After enrolling MFA, generate backup codes and save them in a named note such as:
Service: Example App
Account: you@example.com
Backup codes:
- XXXX-XXXX
- XXXX-XXXX
- XXXX-XXXX
-
Enroll at least two MFA methods
- In your provider’s dashboard, go to
Profile/Avatar → Securityand add a second method, such as an authenticator app plus a security key or backup codes. If one device is lost, you still have another path in.
- In your provider’s dashboard, go to
-
Turn on automatic date/time on all devices used for sign-in
- Phone path:
Settings → Date & Time → Set Automatically - Computer path: enable automatic time and time zone in system settings.
- Phone path:
-
Update your phone number before changing SIMs or devices
- In the provider’s dashboard, go to
Account Settings → Securityand replace the old number while you are still signed in. Test one code before logging out.
- In the provider’s dashboard, go to
-
After changing phones, test MFA before wiping the old device
- Sign in once on the new phone, then sign out and sign back in using the new MFA method. Only erase the old phone after the new one works.
-
Keep a screenshot or note of your enrolled MFA methods
- In
Securitysettings, note whether your account uses authenticator app, SMS, email, security key, or backup codes. This avoids entering the wrong type of code during a stressful lockout.
- In
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI