← Back
Category 14: Channel Security, Account Safety, Phishing & Hack Prevention

Two-factor notifications are delivered to an old phone still controlled by a former operator.

Problem

Two-factor notifications are delivered to an old phone still controlled by a former operator.

Solution

Root Cause / Diagnostic:
When production devices are reassigned or employees depart, administrators frequently forget to remove old hardware from the Google account's trusted 2-Step Verification device list. The former employee retains the ability to intercept or approve 2FA security prompts from their legacy device.

Actionable Fix:
1. 2FA Device List Deprovisioning: Navigate to Google Account > Security > 2-Step Verification > "Your devices" and delete every device not actively in current authorized possession.
2. Remote Device De-registration: Execute a remote sign-out across all legacy hardware via Google Account Device Activity.
3. Device Audit Verification: Confirm that only currently deployed, company-owned smartphones and hardware keys are listed as authorized MFA endpoints.

Pro Tip:
When an employee leaves or you upgrade your studio phones, go into your Google 2-Step Verification settings immediately and delete their old phone from your trusted device list.