---
locale: "en"
updated_at: "2025-10-27T13:32:09.013Z"
canonical: "https://www.isdecisions.com/en/userlock/docs/guides/end-users-mfa-enrollment/recovery-codes"
---

# Manage MFA Recovery Codes

Generate and manage MFA recovery codes for emergencies.

## Introduction

Recovery codes act as a backup authentication method when a user cannot access their MFA device. They ensure continuity of access without compromising security.

#### How recovery codes work

- When a user first configures Multi-Factor Authentication (MFA), UserLock generates a list of recovery codes.
- Each code can be used **only once** to complete authentication.

> **Note**
>
> - If a workstation is **offline **(no network connection), recovery codes remain valid until the next synchronization with the UserLock service.
> - When the workstation reconnects, any previously used codes are automatically marked as used.

## Enable and Configure Recovery Codes

Administrators can enable this option in the **UserLock Console**:

1. Go to ⚙ **Server settings → MFA → Recovery codes**
2. Then enable **Allow recovery codes**.
3. Set the **number of codes** generated per user. Default is 10, but can be adjusted **between 4 and 20 codes** according to your security policy or user needs.

![](https://a.storyblok.com/f/122374/1365x356/a788c631ef/server-settings-mfa-recovery-codes.png)

## Recommendations

To maintain security and usability, consider the following best practices:

- **Educate users** on the purpose of recovery codes and when to use them (only if MFA access is lost).
- **Instruct users** to store their codes in a **secure location**, such as an encrypted password manager or a sealed printed document kept in a safe place.
- **Discourage screenshots** or plain-text digital copies of codes, as they can easily be compromised.
- **Rotate codes periodically** if your organization requires frequent MFA resets.
- **Audit MFA usage** to identify repeated recovery code use, which may indicate device issues or poor MFA adoption.

## Important Notes

- Recovery codes are displayed **only once** during the user’s initial MFA setup.
- They **cannot be recovered or regenerated **later by administrators or users.
- If a user loses their codes, **MFA must be reset** by an administrator.

![](https://a.storyblok.com/f/122374/655x653/5d1e0b05ec/mfa-recovery-codes-8-chiffres.png)
