Two-Factor Authentication: Set It Up, and Recover Access If You Lose Your Device

Updated September 27, 2026 · 5 min read

Two-factor authentication (2FA) adds a second check beyond your password when you sign in to xCloud, using codes from an authenticator app. Setting it up takes a couple of minutes, and knowing how recovery works before you need it is the difference between a quick sign-in and being locked out.

Turn on 2FA

  1. Go to Account Settings → Authentication.
  2. Scan the QR code shown there with an authenticator app on your phone (any standard time-based authenticator app works).
  3. Confirm setup by entering your password and one valid code from the app.
  4. Save your recovery codes somewhere safe before you close the page — you’ll need them if you ever lose access to the authenticator app itself.

Once 2FA is on, every sign-in — including signing in with Google or GitHub — asks for a code from your authenticator app after your password (or after the social provider confirms your identity).

Store your recovery codes safely

Setup creates eight recovery codes. Treat them like a spare key: store them in a password manager or somewhere equally safe, not in an easily accessible plain-text file.

Each recovery code works exactly once. After you use one to sign in, it’s spent and can’t be used again.

You can view or regenerate your recovery codes later from the same Account Settings → Authentication page, after confirming your password. Regenerating replaces every old code with a new set — old codes stop working the moment you regenerate.

Lost your device?

If you still have at least one unused recovery code:

  1. When prompted for your two-factor code at sign-in, enter one of your unused recovery codes instead.
  2. Once you’re back in, set up 2FA again immediately with your new device or a new authenticator app, so you’re not relying on your remaining recovery codes as your only second factor going forward.

No recovery codes either?

If you’ve lost your device and don’t have any unused recovery codes, you can’t recover 2FA from the sign-in screen — contact support. Be ready to verify that you’re the account holder; support needs to confirm your identity before resetting two-factor authentication on your account, since this is exactly the kind of request an attacker who stole your password would also make.

After a suspected compromise

If you think your account or device may have been compromised, beyond just losing the physical device:

  1. Change your password first.
  2. Sign out other sessions. The Browser Sessions page lets you sign out a single session, or all other sessions at once after confirming your password.
  3. Regenerate your recovery codes, since old codes could have been exposed alongside anything else that was compromised.

Still stuck? Contact our support team for any of your queries.

Frequently asked questions

How many recovery codes do I get, and how many times can I use each one?

Setup creates eight recovery codes. Each one works exactly once — after you use it to sign in, it’s spent and won’t work again.

I lost my authenticator app but still have a recovery code. What do I do?

Sign in with the recovery code when prompted for your two-factor code, then immediately set up two-factor authentication again with your new device so you’re not left with just your remaining codes.

I lost my device and all my recovery codes. Is my account gone?

No. Contact support — they can reset two-factor authentication on your account after verifying you’re the account holder. This is a manual, identity-verified process, not something you can do from a locked-out dashboard.

Does signing in with Google or GitHub skip two-factor authentication?

No. If two-factor authentication is enabled on your xCloud account, the two-factor challenge still appears after Google or GitHub verifies your identity.