# Two-Factor Authentication: Set It Up, and Recover Access If You Lose Your Device

> Set up two-factor authentication on your xCloud account, store your recovery codes safely, and get back in if you lose your authenticator device.

Two-factor authentication (2FA) adds a second check beyond your password when you sign in to xCloud, using codes from an authenticator app. Setting it up takes a couple of minutes, and knowing how recovery works before you need it is the difference between a quick sign-in and being locked out.

## Turn on 2FA

1. Go to **Account Settings → Authentication**.
2. Scan the QR code shown there with an authenticator app on your phone (any standard time-based authenticator app works).
3. Confirm setup by entering your password and one valid code from the app.
4. **Save your recovery codes** somewhere safe before you close the page — you'll need them if you ever lose access to the authenticator app itself.

Once 2FA is on, every sign-in — including signing in with Google or GitHub — asks for a code from your authenticator app after your password (or after the social provider confirms your identity).

## Store your recovery codes safely

Setup creates **eight recovery codes**. Treat them like a spare key: store them in a password manager or somewhere equally safe, not in an easily accessible plain-text file.

**Each recovery code works exactly once.** After you use one to sign in, it's spent and can't be used again.

You can view or regenerate your recovery codes later from the same **Account Settings → Authentication** page, after confirming your password. Regenerating replaces every old code with a new set — old codes stop working the moment you regenerate.

## Lost your device?

If you still have at least one unused recovery code:

1. When prompted for your two-factor code at sign-in, enter one of your unused recovery codes instead.
2. Once you're back in, **set up 2FA again immediately** with your new device or a new authenticator app, so you're not relying on your remaining recovery codes as your only second factor going forward.

## No recovery codes either?

If you've lost your device and don't have any unused recovery codes, you can't recover 2FA from the sign-in screen — [contact support](/docs/access-built-in-support-portal-in-xcloud/). Be ready to verify that you're the account holder; support needs to confirm your identity before resetting two-factor authentication on your account, since this is exactly the kind of request an attacker who stole your password would also make.

## After a suspected compromise

If you think your account or device may have been compromised, beyond just losing the physical device:

1. **Change your password** first.
2. **Sign out other sessions.** The **Browser Sessions** page lets you sign out a single session, or all other sessions at once after confirming your password.
3. **Regenerate your recovery codes**, since old codes could have been exposed alongside anything else that was compromised.

Still stuck? Contact our [support team](/docs/access-built-in-support-portal-in-xcloud/) for any of your queries.

## Frequently asked questions

### How many recovery codes do I get, and how many times can I use each one?

Setup creates eight recovery codes. Each one works exactly once — after you use it to sign in, it's spent and won't work again.

### I lost my authenticator app but still have a recovery code. What do I do?

Sign in with the recovery code when prompted for your two-factor code, then immediately set up two-factor authentication again with your new device so you're not left with just your remaining codes.

### I lost my device and all my recovery codes. Is my account gone?

No. Contact support — they can reset two-factor authentication on your account after verifying you're the account holder. This is a manual, identity-verified process, not something you can do from a locked-out dashboard.

### Does signing in with Google or GitHub skip two-factor authentication?

No. If two-factor authentication is enabled on your xCloud account, the two-factor challenge still appears after Google or GitHub verifies your identity.
