How to Prepare for Losing Access to Your Apple Account

Losing every trusted device and number can lock you out for good.

By Kristina Terech - Staff Writer
5 Min Read

One of the most unsettling things that can happen to your device and your data is when you are locked out from your computer. It’s rare, and you can prepare against the possibility so that your recovery is quick—or at least feasible, if not fast.

An ounce of prevention saves a kiloton of cure when it comes to accounts and access. If you follow the following advice ahead of time, you can avoid serious downtime and loss of data.

Keep fresh backups

Backups are the strongest protection you can have against theft, destruction, and loss, including “loss of access.”

If you have daily backups of your Mac and attached drives onsite (via Time Machine or third-party software), copies of your startup volume and external drives offsite, active continuous or daily cloud-hosted backups, or use a sync service to ensure multiple copies and a version history of your active documents, losing access to your Mac still has a sting, but you likely will lose very little data, if any.

You could be like me and do all four. But that’s me.

In some cases, you might be locked out of your current Mac, such as with a FileVault failure or the loss of a Recovery Key. In those cases, you can erase the computer and restore from a full backup, putting you right back in business. Or you may be able to use an external drive or synced files to get back to work on another machine—perhaps a borrowed one—while you plot unlocking the Mac you can’t get to.

Macs that support Activation Lock and have it enabled by turning on Find My Mac require that you can log in to your Apple Account to erase the computer. See how to reset a forgotten Mac password.

With an iPhone or iPad, your biggest job is ensuring you have enough storage in your iCloud+ plan to allow iCloud backups. You can also use a Mac for device backups, but that dramatically increases the odds you’ll be out of date and missing data. With automatic iCloud backups enabled and using iCloud Photos, it’s unlikely you would lose any data—at worst, very little.

Where to keep your passwords

You should have a go-to, secure place for all passwords, passkeys, and other login and encryption keys you may need in the event of a disaster, including:

  • Passwords for one or more administrator accounts on your Mac
  • Passcodes for any iPhones or iPads
  • The Recovery Key for macOS’s FileVault; see where to find your FileVault Recovery Key
  • The account name and password or passkey (or hardware security keys) for your Apple Account (or Accounts)
  • The password for your password manager (which may be the sole item you memorize, and you may also provide a copy to a lawyer, sibling, or trusted party to hold securely)

This secure password repository should preferably be available from a device or location that isn’t tied to where you keep your hardware.

Check your trusted devices and numbers

With two-factor authentication (2FA) enabled on your Apple Account, you might be locked out permanently if you lose access to trusted devices, and trusted phone numbers for SMS and automated voice calls, or can’t find hardware security keys that can be used with an Apple Account.

If you’re using hardware security keys with your Apple Account, Apple already requires that you associate two of them with the account. Always keep one in a place you can get to in an emergency in case the other is lost or destroyed.

Any Apple device logged in to an iCloud account with 2FA active is a so-called trusted device. You can tell that this is working when you try to log in via a browser to the Apple Account website, as every trusted device will display a notification for the 2FA code needed to confirm the login.

If one of your trusted devices doesn’t show that message, check in System Settings/Settings > Account Name that you’re correctly logged in and that you see all the associated devices you expect. If you still can’t get your Apple Account to message trusted devices or the list of devices is missing, you may want to log out of your Apple Account on affected devices and then log back in.

This can take a while and prompt you to answer a lot of questions about synced data—the answer for most is “keep data stored on this device.” When you log back in to iCloud on the device, you agree to merge data, which should avoid duplication and deletion.

You should also check that trusted phone numbers are still properly registered:

  1. Log in at the Apple Account website. If you have Touch ID or Face ID active, click “Use a different Apple Account” and then enter your ID and password.
  2. Instead of entering a 2FA code, click or tap “Didn’t get a verification code?”
  3. Click or tap Text Me. (This will be labeled differently if you marked any or all trusted phone numbers as receiving automatic voice calls instead of text messages.)
  4. Select a trusted number if more than one is available; if only one, Apple texts that number.
  5. Enter the code that’s sent or use the AutoFill option in Safari.

If you never receive the code, log in with a trusted device, check the phone number, and remove and add it. I also recommend having multiple trusted phone numbers as backups.

Changing your phone number has a huge impact in the era of 2FA. You should instead try to transfer your old number to another phone temporarily so you can switch the number listed for various accounts’ 2FA and for iCloud trusted phone numbers.

If you have willing friends, colleagues, or families, having their number as a backup in case your phone isn’t available doesn’t really reduce security, as they would need to know your Apple Account username and password to compromise your security.

Put a PIN on your carrier account

Add a PIN (if you don’t already have one) for account access to your wireless carrier or enable the highest security available for an increasingly rare wired home phone line. Someone who could obtain codes from your phone number might be able to reset your Apple Account and then access iCloud information. (Enabling Advanced Data Protection is one way of preventing that.) Because of accessibility, codes can often be sent both by SMS and by an automated voice system that speaks the code.

Crackers often target people and combine social engineering and easily available online information to convince a customer-service representative that they are the legitimate account holder to get a phone number migrated to a new phone. (Are you likely to be targeted? See whether you need more security than Apple’s defaults. Yet someone may target your account at random to launch attacks.)

The PIN sets a higher bar, because a cracker might have your phone number, financial details, and other information, depending on data breaches floating around.

Keeping your security keys safe

You should treat hardware security keys as if they were irreplaceable keys to the castle—like a passphrase for a cryptocurrency wallet or a password for a vault that self-destructs when you’re one number off in a Dan Brown novel. They’re extremely secure, absolutely vital, and also can be used by other people!

Apple requires that you enroll at least two hardware security keys for an Apple Account. Most sites only require a single hardware key, or won’t let you enroll more than one. If you lose the key, most sites offer a workaround that requires more forms of validation to gain access. Apple does not.

If you can’t find your hardware security keys (or they’re irretrievable, stolen, or busted), but do have access to any of your Apple devices, you can go to Settings/System Settings > Account Name > Sign-In & Security > Two-Factor Authentication > Security Keys and remove all hardware security keys. This requires your device passcode or macOS account password if Stolen Device Protection is disabled, or Touch ID or Face ID if that feature is enabled. Then you can use code-based 2FA to log in to your Apple Account. You can choose to add new security keys if you want to re-enable that level of account security.

Apple has a significant flaw in hardware key management: you can remove all the keys from your Apple Account on an iPhone, iPad, or Mac using only the device passcode or the macOS account password. I feel Apple should demand additional information or another hardware key on the account, since the keys are meant to provide an extra-high level of security.

Enabling Stolen Device Protection requires Face ID or Touch ID to remove all keys. So if you’re concerned about someone gaining access to your device and its associated device or account secret, enable that feature. See how to turn on Stolen Device Protection.

Staff Writer
Follow:
Kristina is a staff writer at GeeksChalk, and is interested in all things Apple. This includes its best products such as the iPad, iPhone, Mac, AirPods, and Apple Watch. When she's not tinkering with the latest Apple gear, you’ll find her watching movies, taking pictures and exploring the great outdoors.
Leave a Comment