Two Factor Authentication: really obvious questions that are never answered

I have resisted turning on 2FA for a number of years after trying it when it was first pushed, because I got into some kind of infinite loop of despair trying to log on. Since I am wondering if one of the reasons I get endless requests to sign in to my Apple id (and always two or three times in a row) I am wondering if turning on 2FA will stop this.


BUT there are two very obvious questions that nobody seems to answer. I will ask these below. The context is that I have a number of Apple devices: an iPhone, two iPads and an Apple TV. When I am locked out of my Apple id on my iPhone I do not want to receive codes on my iPads or Apple TV, this makes no sense as they are almost never with me. Sometimes they are not charged up. They are toys, essentially, but my iPhone is a thing I carry around and actually use.


My questions are:


(1) Can I stop Apple sending codes to my trusted devices without needing to log them out from my Apple id? It makes no sense if I can do this by logging out all my trusted devices (thereby handicapping those devices) but not otherwise.


(2) Assuming I can do (1), or even if I have to use the fallback extra step of requesting a code by SMS, can my trusted phone number be linked to the same iPhone I am trying to log in on? In other words, I want things to behave like I have a single device, which I will always have with me. If I want to log into my Apple id on it, I want to make sure I can get an SMS to the phone even though I am not logged into my Apple id.


Thanks.


MarkH

iPhone SE (3rd generation)

Posted on May 28, 2023 4:24 AM

Reply
Question marked as Top-ranking reply

Posted on May 30, 2023 8:50 AM

Good questions:


The fact that 2FA verification codes are sent to ALL trusted devices isn’t really an issue IMO as:


1) the code can’t be viewed unless an authenticated user is using the device, AND


2) If it ever “pops-up” when YOU didn’t initiate it, you KNOW that someone else has obtained your AppleID password and is attempting to access your AppleID.


Re: Trusted Numbers:


Yes, your iPhone can also be a “Trusted Number” to optionally receive codes via SMS (only when you click “Didn’t Receive Code” option)


… but IMO this is a BAD idea as if your phone is ever stolen, the phone’s physical SIM - removed and installed in the theive’s device - WILL ALSO receive the code. (at least until you notify your carrier)


Also … and often overlooked …


… that your trusted devices - if signed-in - can ALWAYS generate verification codes - even with ZERO connectivity.



Similar questions

21 replies

May 30, 2023 11:00 AM in response to UTBadger

UTBadger wrote:

Your trusted phone number doesn't have to be a device logged in with your Apple ID. It can be any number you trust and verify to be used for verification purposes.


Again, this is infuriatingly vague. The letter of your response seems to admit that the special case of the phone receving the SMS being the same phone that is locked out of the account, but I am drawing attention to the fact that it is a special case and asking if that makes a difference, because intuitively it seems quite likely that it would.


This is outlined in the resource provided above.


I don't want an 'outline', I want specifics. If the resource provided above had given me what I needed I would not be here asking.


MarkH

May 30, 2023 11:29 AM in response to MarkHurst

Re: “… currently I am prompted to log in perhaps twice a week - on four different devices - for absolutely no good reason …


BINGO !!!


NOW we all understand the underpinnings your frustration.


You should NOT - repeat NOT - normally need to use your 2FA credentials IF you are using your Trusted Devices.


(You also should not be “signing out” of your AppleID on your trusted devices.)


In general you only need to use 2FA when adding a new device to your AppleID or when accessing your AppleID data from an “UN-Trusted Device”


Troubleshooting “what might be wrong” perhaps should be handled “device-by-device” in another thread.



May 30, 2023 11:41 AM in response to Chattanoogan

Chattanoogan wrote:

You should NOT - repeat NOT - normally need to use your 2FA credentials IF you are using your Trusted Devices.

(You also should not be “signing out” of your AppleID on your trusted devices.)


I don't know what you're getting at here. Surely all my devices are 'trusted' once I have designated them as such? Assuming 'trusted' means being logged into my Apple id. But for some reason they frequently all spontaneously become 'un-trusted' for no obvious reason. On one occasion about a year ago I went throught the rigmarole of signing out of everything on every device and other suggested voodoo I can't remember, and this seemed to fix it for a few months. But recently it has started again.


My heart sinks at the thought of 'device by device' trouble-shooting, mainly because this doesn't seem device-specific.


MarkH

May 30, 2023 11:56 AM in response to MrHoffman

MrHoffman wrote:
MarkHurst wrote:

Again, this is infuriatingly vague. The letter of your response seems to admit that the special case of the phone receving the SMS being the same phone that is locked out of the account, but I am drawing attention to the fact that it is a special case and asking if that makes a difference, because intuitively it seems quite likely that it would.

I don’t see anything confusing there. Trusted telephone numbers are a telephone network construct, and trusted devices are an Apple authentication and Apple networking construct; a device currently logged into an Apple ID.


It's not confusing, it is an un-answered question. It seems technically possible that Apple could make this a special case, and my layman's understanding of 2FA suggests that they might want to do so.

May 30, 2023 12:17 PM in response to MarkHurst

I don't know what you're getting at here.


That something is wrong … either in setup or usage.


But for some reason they frequently all spontaneously become 'un-trusted' for no obvious reason.


That indeed appears to be the symptom of the as-yet unidentified cause.


My heart sinks at the thought of 'device by device' trouble-shooting,


Understandable, but solutions to technical issues ARE detail-oriented.


Things don’t get fixed with the “Big Picture Overview” and “Generalities” so often presented to “Boardroom Decision Makers”


Odds are that one item will be revealed - applicable to most, if not all cases - and voila - thelight of understandingilluminates.


This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Two Factor Authentication: really obvious questions that are never answered

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.