Problem
Two-factor notifications are delivered to an old phone still controlled by a former operator.
Solution
Root Cause / Diagnostic:
When production devices are reassigned or employees depart, administrators frequently forget to remove old hardware from the Google account's trusted 2-Step Verification device list. The former employee retains the ability to intercept or approve 2FA security prompts from their legacy device.
Actionable Fix:
1. 2FA Device List Deprovisioning: Navigate to Google Account > Security > 2-Step Verification > "Your devices" and delete every device not actively in current authorized possession.
2. Remote Device De-registration: Execute a remote sign-out across all legacy hardware via Google Account Device Activity.
3. Device Audit Verification: Confirm that only currently deployed, company-owned smartphones and hardware keys are listed as authorized MFA endpoints.
Pro Tip:
When an employee leaves or you upgrade your studio phones, go into your Google 2-Step Verification settings immediately and delete their old phone from your trusted device list.
When production devices are reassigned or employees depart, administrators frequently forget to remove old hardware from the Google account's trusted 2-Step Verification device list. The former employee retains the ability to intercept or approve 2FA security prompts from their legacy device.
Actionable Fix:
1. 2FA Device List Deprovisioning: Navigate to Google Account > Security > 2-Step Verification > "Your devices" and delete every device not actively in current authorized possession.
2. Remote Device De-registration: Execute a remote sign-out across all legacy hardware via Google Account Device Activity.
3. Device Audit Verification: Confirm that only currently deployed, company-owned smartphones and hardware keys are listed as authorized MFA endpoints.
Pro Tip:
When an employee leaves or you upgrade your studio phones, go into your Google 2-Step Verification settings immediately and delete their old phone from your trusted device list.