Five interlocking diamond-shaped puzzle pieces in purple, blue, yellow, green, and orange arranged diagonally, symbolizing collaboration and integration.
  • Product Overview
    • Microsoft 365
    • Dynamics HR – Finance & Operations ( F&O )
    • HR in Dynamics Business Central ( BC )
    • Leave & Absence
    • Staff Administration & Digital Personnel Files
    • Time and Attendance
  • Addons
    • AI Mobile Face Clocking In System
  • Product Comparisons
    • vs Personio | Microsoft HR Software Comparison
    • vs Factorial | Microsoft HR Software Comparison
    • vs BambooHR | Microsoft HR Software Comparison
    • vs ADP Workforce Now | Microsoft HR Software Comparison
    • vs Workday | Microsoft HR Software Comparison
    • vs SAP SuccessFactors | Microsoft HR Software Comparison
    • vs HiBob | Microsoft HR Software Comparison
  • Product Overview
    • Microsoft 365
    • Dynamics HR – Finance & Operations ( F&O )
    • HR in Dynamics Business Central ( BC )
    • Leave & Absence
    • Staff Administration & Digital Personnel Files
    • Time and Attendance
  • Addons
    • AI Mobile Face Clocking In System
  • Product Comparisons
    • vs Personio | Microsoft HR Software Comparison
    • vs Factorial | Microsoft HR Software Comparison
    • vs BambooHR | Microsoft HR Software Comparison
    • vs ADP Workforce Now | Microsoft HR Software Comparison
    • vs Workday | Microsoft HR Software Comparison
    • vs SAP SuccessFactors | Microsoft HR Software Comparison
    • vs HiBob | Microsoft HR Software Comparison
Book a Demo

How to Turn 2 Step Verification Off Safely

  • September 27, 2026
How to Turn 2 Step Verification Off Safely

The most popular advice about how to turn 2 step verification off is also the least responsible: open Security, switch it off, and move on. That treats an identity control as a nuisance setting. In practice, the decision affects account recovery, administrator access, employee data and, in Microsoft environments, the security posture inherited by connected HR systems.

The safer question is whether you need to remove 2SV at all. If the problem is a lost phone, repeated prompts, an inaccessible authenticator or an old integration, changing the verification method usually solves the problem without reducing protection. The instructions below explain the mechanics, but also the friction points that commonly lock users out or leave organisations with an undocumented security gap.

Table of Contents

  • Why You Should Think Twice Before Turning 2 Step Verification Off
    • The trade-off differs by account
  • Before You Disable Anything, Get These Prerequisites in Place
    • Prepare the account first
  • How to Turn 2 Step Verification Off on Google, Microsoft and Apple
    • Google accounts
    • Microsoft accounts
    • Apple accounts
  • Turning 2 Step Verification Off Inside Microsoft 365 and Dynamics 365
  • Real-World Scenarios Where Disabling 2 Step Verification Is Justified
    • Lost authenticator and no recovery route
    • Shared kiosks and shift handovers
    • Legacy integrations
    • Non-interactive service accounts
  • Safer Alternatives That Give You the Same Convenience
  • Quick Checklist and When to Speak to a Specialist

Why You Should Think Twice Before Turning 2 Step Verification Off

Turning off 2SV exchanges a second identity check for password-only access. That may feel faster, but a compromised password can then be enough to enter a personal account, Microsoft 365 tenant or HR application. The UK cyber survey reporting shows that only 47% of UK businesses had implemented multi-factor authentication in 2025/2026, leaving 53% without it. Adoption improved from 40% the previous year, while micro-business uptake rose from 35% to 43%, so disabling the control moves an organisation against an already incomplete national baseline.

Account compromise is not an abstract concern. Action Fraud reporting recorded 35,434 reports of social media and email account hacking in 2024, compared with 22,530 in 2023. That is an increase of 12,904 reports, or about 57%, and it makes password-only access a poor default for accounts containing payroll information, employee records, customer correspondence or administrator privileges.

An infographic highlighting the importance of 2-step verification, showcasing risks for businesses and individuals.

The trade-off differs by account

For a consumer account, the exposure may include personal messages, stored payment information and access to other services. For a business account, the blast radius can include an entire Microsoft 365 tenant, delegated mailboxes, Power Platform environments and sensitive HR data.

The inconvenience argument also deserves scrutiny. A prompt takes time, but so does a password reset, an account-recovery investigation or the re-enrolment work required after an administrator removes and later restores a control. Trusted-device behaviour can make the change confusing because an account may continue to recognise an existing session even after future 2SV prompts have been disabled.

Practical rule: If the complaint is “2SV is difficult”, first change the method, device or policy scope. Don't remove the identity control before identifying the actual source of friction.

Useful independent context on remote-work account exposure is available in these Seattle data privacy attorneys tips, particularly when staff use personal networks and unmanaged devices. Most readers searching for this setting will be better served by changing the verification method, not the policy.

Before You Disable Anything, Get These Prerequisites in Place

Treat deactivation as a controlled change. The account should remain recoverable if the platform asks you to authenticate again, if the old device suddenly becomes unavailable or if another administrator needs to restore protection.

Prepare the account first

  1. Strengthen the primary password. Use a unique password or passphrase based on random words, and never reuse it on another service. The NCSC guidance on 2-step verification explains that 2SV adds an extra security step after the password, normally configured from the account's security settings.

  2. Save recovery codes securely. Generate them from the platform's security area and store them offline or in an approved password manager. Don't leave the only copy in the account you're trying to recover.

  3. Keep an alternative method active. A second authenticator installation, backup telephone number, passkey or hardware security key gives you another route if the primary device fails. Microsoft supports authenticator notifications and codes, telephone calls, text messages and security keys, and its sign-in flow includes Sign in another way when a method is unavailable, as described in Microsoft's security information guidance.

  4. Check the recovery mailbox. Confirm that the address works and that it has its own strong authentication. A recovery email that is inaccessible, shared casually or protected only by the same password doesn't provide meaningful resilience.

A graphic titled Prerequisites Before You Disable 2 Step Verification, listing four essential security steps with icons.

The common failure mode is predictable. Someone loses the only phone, can't find recovery codes and then disables 2SV as an attempted fix, only to discover that the platform requires the same missing factor before it permits the change. Prepare the replacement route while you still have a working session.

How to Turn 2 Step Verification Off on Google, Microsoft and Apple

The labels change between operating systems and account types, but the sequence is broadly consistent: open security settings, prove your identity, remove or disable the factor, then test a fresh sign-in. Don't assume that an existing browser session proves the change worked.

Screenshot from https://myaccount.google.com/security

Google accounts

On a Google account, open Google Account, select Security & sign-in, choose 2-Step Verification, authenticate if prompted, then select Turn off and confirm in the pop-up. Google's UK-facing help page notes that you may need to sign in again before the setting can be changed. The documented path is summarised in Google's UK 2-Step Verification help.

This is a four-stage process rather than a single switch:

  1. Open Google Account.
  2. Go to Security & sign-in.
  3. Select 2-Step Verification.
  4. Choose Turn off and confirm.

The reauthentication step is the part most quick guides omit. If you're helping an employee, check that the user has the current password and an available verification method before starting. Once disabled, review recovery options and active sessions rather than assuming every existing trust relationship has disappeared.

Microsoft accounts

For a personal Microsoft account, open account.microsoft.com, go to Security, select Advanced security options, find Two-step verification and choose Turn off. Microsoft describes the relevant account area as Manage how I sign in, where two-step verification can be turned on or off under Additional security. When enabled, sign-ins from untrusted devices can require a code delivered by email, phone or an authenticator app, as set out in Microsoft's two-step verification guidance.

Work and school accounts are different. Entra ID policies, Conditional Access and administrator settings can require MFA even when a user finds a personal-looking switch. If the control is unavailable or returns after you disable it, the tenant policy is probably enforcing the requirement.

Apple accounts

On an Apple device, open Settings, tap your name, choose Sign-In and Security, select Two-Factor Authentication and review whether Apple permits removal for that account and configuration. Apple account controls can vary by account history and security state, so don't rely on an old screenshot or assume the same option exists for every user.

For any platform, sign out completely and test a new sign-in from a controlled device. If you're dealing with GitHub, Facebook, X, Instagram or another SaaS service, look under Security, Login and security or Two-factor authentication. Some services permit removal, while others allow only a method change or require support intervention. Financial and digital-asset services may also restrict complete removal because of their risk and regulatory controls, so a method replacement may be the only supported route.

Turning 2 Step Verification Off Inside Microsoft 365 and Dynamics 365

Microsoft 365 administration requires more care than changing a consumer account. Start by identifying whether the user is governed by per-user MFA, Conditional Access, security defaults or another tenant policy. A user-level change won't override a higher-priority policy.

In the Microsoft Entra admin centre, review the user's authentication and MFA configuration, then inspect Protection and Conditional Access for policies that require MFA. Microsoft changes the location and naming of administrative controls over time, so confirm the current portal labels and permissions before applying a production change. Don't disable a broad policy to solve one employee's device problem. Exclude a narrowly defined account or group only where the organisation's risk decision supports it, and document the reason.

Dynamics 365 and Power Platform workloads inherit identity controls from the tenant. An environment setting doesn't cancel Entra enforcement, and removing a prompt in one layer can leave another layer active. That distinction matters for HRManagement365 deployments, because the tenant administrator controls identity while the HR application uses the upstream Microsoft identity and role model.

Screenshot from https://hrmanagement365.co.uk/wp-content/uploads/entra-mfa-status.png

After the change, sign out of Microsoft 365 fully, close existing browser sessions and test the account again. Check the relevant Power Platform and Dynamics 365 environment separately, then record the change, approver, scope and restoration plan in the tenant change log. A screenshot alone isn't an audit record because it rarely captures why the decision was made or when protection must be restored.

Real-World Scenarios Where Disabling 2 Step Verification Is Justified

Disabling 2SV can be defensible when it is a short, controlled response to a genuine access problem. It becomes poor practice when it is used as a permanent substitute for fixing identity design.

A diagram outlining four common, justified scenarios for temporarily disabling two-step verification for account security access.

Lost authenticator and no recovery route

If a business-critical user has lost the only authenticator and recovery codes, a temporary administrative recovery action may be reasonable. Restore access, replace the factor and re-enrol the user immediately. The safer long-term answer is secondary methods and documented recovery ownership.

Shared kiosks and shift handovers

A shared HR, warehouse or contact-centre terminal is a poor place for a prompt tied to one employee's phone. Instead of removing protection from a personal account, use individual identities with a device-bound passkey, or redesign the workflow around a properly governed shared-device model.

Legacy integrations

Older SMTP, IMAP or POP connections and some historic automation flows may not support modern authentication. A narrowly scoped exception, approved app password where supported, or replacement integration is safer than disabling MFA for a human administrator.

Non-interactive service accounts

Some service accounts cannot complete interactive MFA. Don't solve that by weakening employee accounts. Move the workload towards managed identities, certificates or another supported machine-to-machine authentication pattern, with ownership and rotation recorded.

Safer Alternatives That Give You the Same Convenience

Most requests to turn 2SV off are requests to remove a particular annoyance. Passkeys address the repeated-code problem by using a device-bound credential, such as Windows Hello or an Apple device credential. A FIDO2 security key provides another option for staff who travel, work across sites or regularly lose access to a phone.

Microsoft Authenticator can replace SMS with an app notification or code, and number matching reduces the chance that a user approves an unexpected prompt by mistake. If the issue is prompt volume, review session controls and Conditional Access rather than removing MFA everywhere. A trusted corporate device or carefully scoped low-risk exception may reduce daily interruption while retaining stronger checks for unfamiliar sign-ins.

Better design: Keep the second factor, then remove the unnecessary journey around it.

Recovery arrangements matter as much as the sign-in method. Store recovery codes in an approved password manager, retain an offline copy under controlled access and assign responsibility for replacing a lost device. Guidance such as this MFA setup for regulated businesses is useful when an organisation needs to connect user experience with formal security governance.

For Microsoft-centric HR teams, HRManagement365 is a UK and EU HR solution powered by Hubdrive and Microsoft. It is based on Dynamics 365, Power Platform and Dataverse, and can be configured or extended with integrations, workflows, Power Apps, Power Automate solutions and custom HR applications. Because identity is managed upstream in Microsoft 365, the right fix may sit in tenant policy, device registration or role design rather than inside the HR process itself.

Quick Checklist and When to Speak to a Specialist

Before you disable anything, confirm each point:

  • Recovery codes: Save them securely and make sure they're usable.
  • Registered methods: Replace or remove authenticators that are lost, obsolete or assigned to the wrong person.
  • Primary password: Confirm it's unique, strong and not shared.
  • Change record: Log the decision, scope, approver and restoration action.
  • Shared administration: Tell the IT owner before changing a shared or privileged account.
  • Restoration date: Set a calendar reminder to re-enable 2SV after the underlying issue is fixed.

Speak to a specialist if Conditional Access re-enrols the user on its own, or if disabling protection breaks a shared mailbox or delegated-access workflow. Those symptoms usually indicate that the account is governed by a broader identity architecture, not a simple personal setting.

For UK organisations, tenant changes may also need to align with internal controls supporting Cyber Essentials, ISO 27001 or FCA operational resilience requirements. HRManagement365 can help connect Microsoft identity decisions with HR roles, employee lifecycle workflows, Dataverse security and Dynamics 365 integrations without treating authentication as an isolated toggle.


Speak to an HRManagement365 specialist about configuring Microsoft 365 identity controls alongside connected HR processes, integrations and employee lifecycle workflows across the UK and EU. Discover how HR Management 365 can help improve, connect and automate your HR processes, then phone +44 1522 508096 today or send us a message.

author avatar
Chris Pickles Director | Dynamics 365, Power Platform & HR Solutions Architect
I help HR leaders get off the admin hamster wheel with a Dynamics-based HR Management solution built on Hubdrive. HRManagement365 gives organisations a flexible HR platform within the Microsoft ecosystem that can be easily customised around the way they already work — rather than forcing teams into rigid, one-size-fits-all processes. It can be tailored to your HR workflows, integrated with Microsoft Dynamics 365 Business Central (BC) and Finance & Operations (F&O), and extended with Microsoft Power Platform to automate processes and connect HR more closely with the wider business. For employees, the experience stays familiar. They can interact with HR processes through the Microsoft tools they already know and use every day, including Teams, Outlook, Word and Power BI, helping drive adoption without introducing another unfamiliar system. The goal is simple: less manual admin, better-connected processes and an HR solution that fits your organisation. If you’re using Microsoft Dynamics and want HR to work as part of the same ecosystem, ask me about HRManagement365.
See Full Bio
Digital Transformation Microsoft Power Platform Power Apps Power Automate Power BI Dynamics 365 HR / HR Systems Business Process Automation Hubdrive HR
Previous
Next

Related Posts

Leave of Absence UK: A Practical Guide for Employers

Leave of Absence UK: A Practical Guide for Employers

A Manchester operations manager starts the week with two sickness absence cases, three annual leave requests and a bereavement notification. Each request

Read More
10 Headcount Planning Template Resources

10 Headcount Planning Template Resources

The budget review is approaching, and HR and finance are working from a spreadsheet that contains current employees, planned hires, vacancies, proposed

Read More

Ready to modernise HR in your Microsoft environment?

Build on Microsoft 365, Power Platform, Business Central or Dynamics 365 Human Resources with HR Management 365 powered by Hubdrive.

Talk to a Expert Today
Five interlocking diamond-shaped puzzle pieces in purple, blue, yellow, green, and orange arranged diagonally, symbolizing collaboration and integration.

Empower your workforce with HR Management for Microsoft Dynamics 365 by Hubdrive.

  • hello@hrmanagement365.com
  • 01522 508096
  • Unit 2, Kingsley Court, Kingsley Road, Lincoln, LN6 3TA, UK
Product
  • Overview
  • Finance and Operations
  • Business Central
  • Leave and Absence
  • Staff Administration and Digital Personnel Files
  • Time and Attendance
Our Plugins
  • AI Faceclocking
  • Right to Work
About
  • About Us
  • Contact
  • Articles & News

© 2026 HRManagement365