The most popular advice about how to turn 2 step verification off is also the least responsible: open Security, switch it off, and move on. That treats an identity control as a nuisance setting. In practice, the decision affects account recovery, administrator access, employee data and, in Microsoft environments, the security posture inherited by connected HR systems.
The safer question is whether you need to remove 2SV at all. If the problem is a lost phone, repeated prompts, an inaccessible authenticator or an old integration, changing the verification method usually solves the problem without reducing protection. The instructions below explain the mechanics, but also the friction points that commonly lock users out or leave organisations with an undocumented security gap.
Table of Contents
- Why You Should Think Twice Before Turning 2 Step Verification Off
- Before You Disable Anything, Get These Prerequisites in Place
- How to Turn 2 Step Verification Off on Google, Microsoft and Apple
- Turning 2 Step Verification Off Inside Microsoft 365 and Dynamics 365
- Real-World Scenarios Where Disabling 2 Step Verification Is Justified
- Safer Alternatives That Give You the Same Convenience
- Quick Checklist and When to Speak to a Specialist
Why You Should Think Twice Before Turning 2 Step Verification Off
Turning off 2SV exchanges a second identity check for password-only access. That may feel faster, but a compromised password can then be enough to enter a personal account, Microsoft 365 tenant or HR application. The UK cyber survey reporting shows that only 47% of UK businesses had implemented multi-factor authentication in 2025/2026, leaving 53% without it. Adoption improved from 40% the previous year, while micro-business uptake rose from 35% to 43%, so disabling the control moves an organisation against an already incomplete national baseline.
Account compromise is not an abstract concern. Action Fraud reporting recorded 35,434 reports of social media and email account hacking in 2024, compared with 22,530 in 2023. That is an increase of 12,904 reports, or about 57%, and it makes password-only access a poor default for accounts containing payroll information, employee records, customer correspondence or administrator privileges.
The trade-off differs by account
For a consumer account, the exposure may include personal messages, stored payment information and access to other services. For a business account, the blast radius can include an entire Microsoft 365 tenant, delegated mailboxes, Power Platform environments and sensitive HR data.
The inconvenience argument also deserves scrutiny. A prompt takes time, but so does a password reset, an account-recovery investigation or the re-enrolment work required after an administrator removes and later restores a control. Trusted-device behaviour can make the change confusing because an account may continue to recognise an existing session even after future 2SV prompts have been disabled.
Practical rule: If the complaint is “2SV is difficult”, first change the method, device or policy scope. Don't remove the identity control before identifying the actual source of friction.
Useful independent context on remote-work account exposure is available in these Seattle data privacy attorneys tips, particularly when staff use personal networks and unmanaged devices. Most readers searching for this setting will be better served by changing the verification method, not the policy.
Before You Disable Anything, Get These Prerequisites in Place
Treat deactivation as a controlled change. The account should remain recoverable if the platform asks you to authenticate again, if the old device suddenly becomes unavailable or if another administrator needs to restore protection.
Prepare the account first
-
Strengthen the primary password. Use a unique password or passphrase based on random words, and never reuse it on another service. The NCSC guidance on 2-step verification explains that 2SV adds an extra security step after the password, normally configured from the account's security settings.
-
Save recovery codes securely. Generate them from the platform's security area and store them offline or in an approved password manager. Don't leave the only copy in the account you're trying to recover.
-
Keep an alternative method active. A second authenticator installation, backup telephone number, passkey or hardware security key gives you another route if the primary device fails. Microsoft supports authenticator notifications and codes, telephone calls, text messages and security keys, and its sign-in flow includes Sign in another way when a method is unavailable, as described in Microsoft's security information guidance.
-
Check the recovery mailbox. Confirm that the address works and that it has its own strong authentication. A recovery email that is inaccessible, shared casually or protected only by the same password doesn't provide meaningful resilience.
The common failure mode is predictable. Someone loses the only phone, can't find recovery codes and then disables 2SV as an attempted fix, only to discover that the platform requires the same missing factor before it permits the change. Prepare the replacement route while you still have a working session.
How to Turn 2 Step Verification Off on Google, Microsoft and Apple
The labels change between operating systems and account types, but the sequence is broadly consistent: open security settings, prove your identity, remove or disable the factor, then test a fresh sign-in. Don't assume that an existing browser session proves the change worked.
Google accounts
On a Google account, open Google Account, select Security & sign-in, choose 2-Step Verification, authenticate if prompted, then select Turn off and confirm in the pop-up. Google's UK-facing help page notes that you may need to sign in again before the setting can be changed. The documented path is summarised in Google's UK 2-Step Verification help.
This is a four-stage process rather than a single switch:
- Open Google Account.
- Go to Security & sign-in.
- Select 2-Step Verification.
- Choose Turn off and confirm.
The reauthentication step is the part most quick guides omit. If you're helping an employee, check that the user has the current password and an available verification method before starting. Once disabled, review recovery options and active sessions rather than assuming every existing trust relationship has disappeared.
Microsoft accounts
For a personal Microsoft account, open account.microsoft.com, go to Security, select Advanced security options, find Two-step verification and choose Turn off. Microsoft describes the relevant account area as Manage how I sign in, where two-step verification can be turned on or off under Additional security. When enabled, sign-ins from untrusted devices can require a code delivered by email, phone or an authenticator app, as set out in Microsoft's two-step verification guidance.
Work and school accounts are different. Entra ID policies, Conditional Access and administrator settings can require MFA even when a user finds a personal-looking switch. If the control is unavailable or returns after you disable it, the tenant policy is probably enforcing the requirement.
Apple accounts
On an Apple device, open Settings, tap your name, choose Sign-In and Security, select Two-Factor Authentication and review whether Apple permits removal for that account and configuration. Apple account controls can vary by account history and security state, so don't rely on an old screenshot or assume the same option exists for every user.
For any platform, sign out completely and test a new sign-in from a controlled device. If you're dealing with GitHub, Facebook, X, Instagram or another SaaS service, look under Security, Login and security or Two-factor authentication. Some services permit removal, while others allow only a method change or require support intervention. Financial and digital-asset services may also restrict complete removal because of their risk and regulatory controls, so a method replacement may be the only supported route.
Turning 2 Step Verification Off Inside Microsoft 365 and Dynamics 365
Microsoft 365 administration requires more care than changing a consumer account. Start by identifying whether the user is governed by per-user MFA, Conditional Access, security defaults or another tenant policy. A user-level change won't override a higher-priority policy.
In the Microsoft Entra admin centre, review the user's authentication and MFA configuration, then inspect Protection and Conditional Access for policies that require MFA. Microsoft changes the location and naming of administrative controls over time, so confirm the current portal labels and permissions before applying a production change. Don't disable a broad policy to solve one employee's device problem. Exclude a narrowly defined account or group only where the organisation's risk decision supports it, and document the reason.
Dynamics 365 and Power Platform workloads inherit identity controls from the tenant. An environment setting doesn't cancel Entra enforcement, and removing a prompt in one layer can leave another layer active. That distinction matters for HRManagement365 deployments, because the tenant administrator controls identity while the HR application uses the upstream Microsoft identity and role model.
After the change, sign out of Microsoft 365 fully, close existing browser sessions and test the account again. Check the relevant Power Platform and Dynamics 365 environment separately, then record the change, approver, scope and restoration plan in the tenant change log. A screenshot alone isn't an audit record because it rarely captures why the decision was made or when protection must be restored.
Real-World Scenarios Where Disabling 2 Step Verification Is Justified
Disabling 2SV can be defensible when it is a short, controlled response to a genuine access problem. It becomes poor practice when it is used as a permanent substitute for fixing identity design.
Lost authenticator and no recovery route
If a business-critical user has lost the only authenticator and recovery codes, a temporary administrative recovery action may be reasonable. Restore access, replace the factor and re-enrol the user immediately. The safer long-term answer is secondary methods and documented recovery ownership.
Shared kiosks and shift handovers
A shared HR, warehouse or contact-centre terminal is a poor place for a prompt tied to one employee's phone. Instead of removing protection from a personal account, use individual identities with a device-bound passkey, or redesign the workflow around a properly governed shared-device model.
Legacy integrations
Older SMTP, IMAP or POP connections and some historic automation flows may not support modern authentication. A narrowly scoped exception, approved app password where supported, or replacement integration is safer than disabling MFA for a human administrator.
Non-interactive service accounts
Some service accounts cannot complete interactive MFA. Don't solve that by weakening employee accounts. Move the workload towards managed identities, certificates or another supported machine-to-machine authentication pattern, with ownership and rotation recorded.
Safer Alternatives That Give You the Same Convenience
Most requests to turn 2SV off are requests to remove a particular annoyance. Passkeys address the repeated-code problem by using a device-bound credential, such as Windows Hello or an Apple device credential. A FIDO2 security key provides another option for staff who travel, work across sites or regularly lose access to a phone.
Microsoft Authenticator can replace SMS with an app notification or code, and number matching reduces the chance that a user approves an unexpected prompt by mistake. If the issue is prompt volume, review session controls and Conditional Access rather than removing MFA everywhere. A trusted corporate device or carefully scoped low-risk exception may reduce daily interruption while retaining stronger checks for unfamiliar sign-ins.
Better design: Keep the second factor, then remove the unnecessary journey around it.
Recovery arrangements matter as much as the sign-in method. Store recovery codes in an approved password manager, retain an offline copy under controlled access and assign responsibility for replacing a lost device. Guidance such as this MFA setup for regulated businesses is useful when an organisation needs to connect user experience with formal security governance.
For Microsoft-centric HR teams, HRManagement365 is a UK and EU HR solution powered by Hubdrive and Microsoft. It is based on Dynamics 365, Power Platform and Dataverse, and can be configured or extended with integrations, workflows, Power Apps, Power Automate solutions and custom HR applications. Because identity is managed upstream in Microsoft 365, the right fix may sit in tenant policy, device registration or role design rather than inside the HR process itself.
Quick Checklist and When to Speak to a Specialist
Before you disable anything, confirm each point:
- Recovery codes: Save them securely and make sure they're usable.
- Registered methods: Replace or remove authenticators that are lost, obsolete or assigned to the wrong person.
- Primary password: Confirm it's unique, strong and not shared.
- Change record: Log the decision, scope, approver and restoration action.
- Shared administration: Tell the IT owner before changing a shared or privileged account.
- Restoration date: Set a calendar reminder to re-enable 2SV after the underlying issue is fixed.
Speak to a specialist if Conditional Access re-enrols the user on its own, or if disabling protection breaks a shared mailbox or delegated-access workflow. Those symptoms usually indicate that the account is governed by a broader identity architecture, not a simple personal setting.
For UK organisations, tenant changes may also need to align with internal controls supporting Cyber Essentials, ISO 27001 or FCA operational resilience requirements. HRManagement365 can help connect Microsoft identity decisions with HR roles, employee lifecycle workflows, Dataverse security and Dynamics 365 integrations without treating authentication as an isolated toggle.
Speak to an HRManagement365 specialist about configuring Microsoft 365 identity controls alongside connected HR processes, integrations and employee lifecycle workflows across the UK and EU. Discover how HR Management 365 can help improve, connect and automate your HR processes, then phone +44 1522 508096 today or send us a message.