Password · guide

How to turn off two factor authentication where you still can

By Alberto Gulotta · Updated · 14 min read

How to turn off two factor authentication: sign in first, then find it in the account’s security settings — on Google, under 2-Step Verification; on a Microsoft account, under Manage how I sign in. Then two clean-ups. On some accounts the switch no longer exists at all.

Where the switch is, and what each service says happens when you use it
ServiceWhere the switch isWhat it warns aboutSource
Google Security & sign-in, “How you sign in to Google”, 2-Step Verification, Turn off Destroy your saved backup codes; revoke app passwords, or you “may get errors” Google
Microsoft account.microsoft.com/security, Manage how I sign in, Two-step verification, Turn off App passwords stop being available at all once it is offMicrosoft
GitHub Authentication settings, if the option is there “You may lose access to organizations you belong to”; for enrolled contributors “you cannot disable 2FA”GitHub
Two different questions that arrive at the same search Wanting the feature off and being unable to get in are opposite problems. One is a settings change; the other is account recovery, which starts from the sign-in page. “I do not want the prompts” “I cannot get in” A settings change Sign in first, then the security settings. Two clean-ups afterwards. Account recovery Starts at the sign-in page, not in settings you cannot reach. A different journey. AI Tools Primer · figure
Splitting these two apart is the first thing worth doing, because the answer to one is of no use at all for the other.
  1. First decide whether you want it off, or want back in. These lead to opposite places. If you have lost the phone, turning the feature off is not the route — account recovery is, and it starts from the sign-in page rather than from the settings you cannot reach.
  2. Check whether the option exists for you at all. GitHub is explicit that for some accounts it does not: “if you are part of the group that GitHub is requiring to enroll in 2FA in 2023, you cannot disable 2FA. A banner will display in your authentication settings to remind you that you are not allowed to disable 2FA.”
  3. On Google: Security & sign-in, then 2-Step Verification, then Turn off. Google’s own path, and its own framing before you start: “if you turn off 2-Step Verification, you remove an additional layer of security, which can make it easier for someone else to access your account.”
  4. On a Microsoft account: account.microsoft.com/security, Manage how I sign in, then Turn off. Microsoft puts the switch under “Additional security and Two-step verification”, with Turn on and Turn off in the same place.
  5. Then destroy the backup codes. This is Google’s instruction, not ours: “destroy all the backup codes that you’ve saved for signing in to this account.” Codes printed for an account that no longer uses them are a set of keys with nothing to say who holds them.
  6. Then revoke the app passwords. Google: “if you use app passwords to let apps access your Google Account, you may get errors when you turn off 2-Step Verification”, and it recommends removing them. Microsoft states the same dependency from the other end: “app passwords are only available if you use two-step verification.” And while it is on, codes will keep arriving — including, occasionally, ones nobody asked for.
  7. If the goal was fewer prompts rather than less security, stop here and change method instead. A passkey or a security key on the same account removes the typing without removing the protection, and it is a change in the same settings screen.
The switch, and the two clean-ups that follow it Turn the feature off, then destroy the saved backup codes, then revoke the app passwords. Both clean-ups are named by the services themselves. One switch, two clean-ups 1. Turn it off In the account’s own security settings. 2. Backup codes Google: “destroy all the backup codes” you saved. 3. App passwords Revoke them, or expect errors from those apps. AI Tools Primer · figure
The two boxes on the right are the part that gets left out. Both instructions come from Google’s own page about turning the feature off.

The two clean-ups

Turning the feature off is one click. What it leaves behind is two sets of credentials that were only ever meant to exist alongside it — and not one of the five results on the first page for this question on 29 August 2026 said so.

Backup codes stay valid unless you get rid of them Google’s page on turning 2-Step Verification off ends with an instruction rather than a congratulation: “destroy all the backup codes that you’ve saved for signing in to this account.” They were printed as a way in for a day when nothing else worked, and a way in does not stop being one because a setting changed.
App passwords become errors, and Google says so in advance “If you use app passwords to let apps access your Google Account, you may get errors when you turn off 2-Step Verification.” Its remedy is to revoke them and let each app ask for the ordinary password again — and it warns that the timing is loose: “if an app doesn’t ask right away, it might take longer to recognize that its app password has been revoked.”
And on a Microsoft account the dependency runs the other way “App passwords are only available if you use two-step verification. If you don’t have two-step verification turned on, you won’t see the App passwords section.” So anything relying on one — older mail apps, some devices — loses the arrangement it was set up with, and the section where you would fix it disappears at the same moment.
Three cases where the option is not yours to use Enrolled GitHub contributors cannot disable it. An outside collaborator must leave the organisation first. And a member of an organisation that requires it loses access. Where the switch is missing or costly Enrolled contributors “You cannot disable 2FA”, and a banner in settings says so. Outside collaborators “You must first leave the organization before you can disable 2FA.” Organisation members “You’ll lose your access to their repositories” until you re-enable it. AI Tools Primer · figure
All three are GitHub’s own wording. They are worth reading before the switch, because two of them take effect the moment it is flipped.

When the option is not there, and why that is increasingly the answer

GitHub states the case where it simply cannot be done. “If you are part of the group that GitHub is requiring to enroll in 2FA in 2023, you cannot disable 2FA. A banner will display in your authentication settings to remind you that you are not allowed to disable 2FA.” That is not a bug and not a missing menu: it is the account’s state.

And it states two more where it can be done and costs something. For a member or billing manager of an organisation that requires the feature: “you’ll lose your access to their repositories”, and the way back is the way out — “to regain access to the organization, re-enable 2FA”. For an outside collaborator: “you must first leave the organization before you can disable 2FA.”

Elsewhere the ground is moving in the same direction. Microsoft’s page on two-step verification notes that it is “phasing out SMS as a method of authentication and account recovery for personal Microsoft accounts”. A method being withdrawn is not the same as the feature being compulsory, but it is the same current: the number of accounts where this switch exists is going down rather than up.

Which makes the honest version of this page short. Where the switch exists, it is three clicks and two clean-ups. Where it does not, no amount of looking will find it, and the useful move is to change the method rather than remove the layer.

The question underneath this one is usually a different question. Two very different situations arrive at the same search. In the first, the feature works and it is a nuisance: a code every morning on a laptop that never leaves the house. In the second, the phone is gone, or the authenticator was wiped with it, and turning the feature off looks like the way back in. It is not. Every switch on this page sits behind a completed sign-in, which is exactly what the second situation does not have. The route there is account recovery, from the sign-in page, using whatever second method was registered — and if none was, a conversation with the service.

Google states the cost before it states the steps. Its page opens with the consequence rather than the steps: “2-Step Verification makes your account more secure. If you turn off 2-Step Verification, you remove an additional layer of security, which can make it easier for someone else to access your account.” That framing is worth borrowing before you do it anywhere, because it is the accurate description of the trade. Nothing else changes; one layer is removed, and a password on its own becomes sufficient.

The clean-ups matter because they leave real keys lying around. A backup code is not a reminder, it is a credential: a string that opens the account when nothing else will. A sheet of them printed in 2024 and left in a drawer keeps that property after the feature is off, which is why Google’s instruction is to destroy them rather than to file them. App passwords have the same shape from the other direction — long strings granted to a mail client or a device, each of them a way in that outlives the arrangement that created it.

If the real complaint is the typing, there is a better change in the same screen. A passkey or a hardware key on the account removes the daily code without removing the second factor: the browser and the device check each other, and there is nothing to read out, type or lose. That is a change of method rather than a removal of protection, and on most of the services in the table above it lives two rows below the switch this page is about.

The Google steps, the warning about backup codes and app passwords and the framing about removing a layer are quoted from Google Account Help. The GitHub sentences about accounts that cannot disable the feature, about outside collaborators and about losing access to organisations are quoted from GitHub Docs. The Microsoft path, the note about app passwords and the line about phasing out SMS are quoted from Microsoft Support. All three were read on 7 September 2026.

Where to start

Four ways in.

“Where is the switch?”
One table, above — then the two clean ups
“The option is not there.”
For some accounts it is gone — when there is no switch
“My apps stopped working.”
App passwords — the two clean ups
“I only want fewer prompts.”
Change the method instead — a better change

The two clean-ups

Backup codes and app passwords are credentials that outlive the setting that created them. Both services name them, and both are easy to leave behind.

When there is no switch

GitHub enrolled a group of contributors and removed the option for them. Elsewhere methods are being withdrawn. The number of accounts with this switch is falling.

A better change

A passkey or a hardware key removes the daily typing without removing the second factor. It usually sits two rows below the switch.

If you are locked out

Every switch here sits behind a completed sign-in, which is the thing a locked-out account does not have. That is recovery, and it starts elsewhere.

Questions people also ask

How do I turn off two-factor authentication on a Google account?

Security & sign-in, then under “How you sign in to Google” tap 2-Step Verification, then Turn off and confirm. Google then asks you to destroy your saved backup codes and to revoke any app passwords.

What if I do not want two-factor authentication?

On some accounts that is no longer a choice. GitHub: “if you are part of the group that GitHub is requiring to enroll in 2FA in 2023, you cannot disable 2FA.” Where it can be switched off, the service will usually say what you lose.

Do my backup codes still work after I turn it off?

They are a way in that was created deliberately, which is why Google’s own instruction is to “destroy all the backup codes that you’ve saved for signing in to this account” once the feature is off.

Why do my apps stop working after I turn it off?

App passwords. Google warns you “may get errors” and recommends revoking them; Microsoft states that “app passwords are only available if you use two-step verification”, so the section itself disappears.

I have lost my phone and cannot sign in. Is this the right page?

No. That is account recovery, which starts from the sign-in page rather than from settings you cannot reach. Turning the feature off requires being signed in first.

Not covered here. It will not cover every service. The three here are the ones whose own documentation states a consequence rather than only a path.

It will not help with an account you cannot sign into. That is recovery, and it begins at the sign-in page.

And it will not recommend turning the feature off. It will tell you where the switch is, what each service says it costs, and what it leaves behind. What holds instead is simple: every consequence on this page is quoted from the service’s own documentation, with the date it was read, rather than summarised from memory.

Sources

  1. Google Account Help — Turn off 2-Step Verification: the path through Security & sign-in, the statement about removing a layer of security, the instruction to destroy saved backup codes, and the warning about app passwords — support.google.com, read 7 September 2026.
  2. GitHub Docs — Disabling two-factor authentication for your personal account: the accounts that cannot disable it, the loss of access for organisation members, and the requirement for outside collaborators to leave first — docs.github.com, read 7 September 2026.
  3. Microsoft Support — How to use two-step verification with your Microsoft account: where the switch lives, that app passwords exist only while it is on, and the phasing out of SMS for personal accounts — support.microsoft.com, read 7 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 7 September 2026 · last checked 10 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.