How is access recovery controlled?

Identity is reverified

Recovery requests are received through an approved organizational channel. The requester’s identity is reverified before a replacement factor is enrolled. A username alone is not accepted as sufficient evidence for recovery.

The previous factor is disabled

Once the request is verified, the unavailable factor is disabled and related access is reviewed under organizational policy. The actions taken are recorded so that subsequent investigation and event review are supported.

A replacement factor is enrolled and the outcome is communicated

The new factor is enrolled through an approved process and the account owner is notified. Sign-in with the replacement factor is checked, and the support request is closed once the process is complete. The procedure is also adapted for planned device replacement.

A lost-device scenario

When a phone is reported lost, the report time, affected account and exposed authenticators are recorded. The request is handled through the established support channel; a changed contact number alone is not treated as sufficient identity evidence. Temporary restrictions and necessary access are determined under organizational policy. Passwords and one-time codes are excluded from ticket content.

What evidence closes a recovery request?

The case owner, verification method, revoked authenticator and replacement enrollment time are retained in the record. Sign-in with the new authenticator is tested and the old authenticator’s status is checked. Notification is sent through an established channel so unexpected changes can be investigated. Signs of misuse trigger incident handling rather than routine recovery alone.

Reference and scope

This planning guide is applied in accordance with organizational policy and documented system capabilities.

NIST SP 800-63B-4 — Authentication and Authenticator Management
Sadid authentication methodsBlog index