Skip to main content
Workflow

Recover shared authenticator access

How to recover shared TOTP/authenticator access during outages, device loss, or enrollment owner unavailability—without Slack screenshot chains.

Recovery scenarios

Common cases: enrollment owner on PTO during outage; device loss; accidental removal of all viewers; vendor forced MFA reset.

Prevention beats recovery—centralize team authentication so MFA does not live on one personal phone.

Trust and evidence

Recovery actions should be ticketed. Pair technical steps with security overview expectations for break-glass.

Operationalize this workflow with MultiMFA

Governed SMS and TOTP for collective logins—14-day trial.

Recovery workflow steps

Break-glass recovery without screenshot chains.

  1. Confirm break-glass criteria

    Incident commander authorizes temporary viewer expansion per runbook.

  2. Use MultiMFA admin

    Existing admins add on-call viewers to enrollment—no QR re-scan if enrollment intact.

  3. Vendor recovery path

    If enrollment lost, follow vendor account recovery; re-enroll into MultiMFA once access restored.

  4. Avoid screenshot relay

    Do not paste TOTP in war rooms—use viewer dashboard as approved channel.

  5. Contract access post-incident

    Remove temporary viewers when incident closes—see emergency access workflow.

Glossary

Key terms in this guide

Operational definitions for shared MFA vocabulary—written for security and IT teams, not dictionary-only summaries.

Workflow FAQ

Does MultiMFA replace our IdP MFA?
No. MultiMFA governs second factors for shared operational logins. Workforce SSO MFA remains on your identity provider.
How fast can we revoke access?
Admins remove viewers/recipients in MultiMFA immediately—faster than resetting vendor MFA on personal phones across many apps.
What if the only phone with Google Authenticator left?
Treat as enrollment loss: vendor recovery + migrate to MultiMFA TOTP with governed viewers. See how to share Google Authenticator resource.

More questions? Contact support or read our security overview.

Reduce operational MFA friction

Named viewers, admin revoke, and audit-friendly workflows.