# Recovery Codes & Backup Keys

When setting up two-factor authentication, most services provide one-time recovery codes. These are the "break glass" option if the authenticator app and security keys are both unavailable.

## Where Recovery Codes Are Stored

*\[e.g., "Printed and stored in the fireproof safe," "Saved as a secure note in the password manager," "In a text file on the encrypted USB drive in the safe"\]*

## Recovery Codes by Service

<table id="bkmrk-servicerecovery-code"><tr><th>Service</th><th>Recovery Codes Location</th><th>Notes</th></tr><tr><td>Google</td><td>*\[Location\]*</td><td></td></tr><tr><td>Apple ID</td><td>*\[Location\]*</td><td>*\[Recovery key? Trusted phone number?\]*</td></tr><tr><td>Microsoft</td><td>*\[Location\]*</td><td></td></tr><tr><td>Password Manager</td><td>*\[Location\]*</td><td>*\[Most critical one\]*</td></tr><tr><td>*\[Other critical service\]*</td><td>*\[Location\]*</td><td></td></tr></table>

## Encrypted USB / Backup Drive

*\[If you keep recovery codes or sensitive files on an encrypted USB drive, where is it and what's the decryption password?\]*

<table id="bkmrk-location%5Bwhere-the-u"><tr><td>**Location**</td><td>*\[Where the USB drive is\]*</td></tr><tr><td>**Encryption Method**</td><td>*\[e.g., BitLocker, VeraCrypt\]*</td></tr><tr><td>**Password**</td><td>*\[Where to find it\]*</td></tr></table>