Intuit Account Lockouts: Why Two-Step Verification Matters Now
QuickBooks users are getting locked out of Intuit accounts. Setting up multiple verification methods — phone, email, passkeys, authenticator apps — can prevent it.

QuickBooks users who lose access to their Intuit Account often discover too late that a single forgotten password or an outdated phone number is all it takes to lock them out of their company files. The problem has grown common enough that Intuit now promotes a suite of verification tools designed to keep access recoverable — but many users have not configured them until after a lockout occurs.
Why Users Get Locked Out
The Intuit Account serves as the gateway to QuickBooks Online, QuickBooks Desktop subscriptions, payroll services, and associated products. When a user cannot sign in, the entire workflow stalls. The most common causes are straightforward: a forgotten password, a phone number that has changed since the account was created, or an email address the user no longer can access.
Without a backup verification method on file, recovering the account becomes significantly harder. Users may be asked to submit identity documents — a driver’s license, state ID, passport, or notarized paperwork — through a proof-of-identity form. That process takes time, and during busy periods it can leave a business without access to its books for days.
Verification Methods Worth Setting Up Before You Need Them
Within the Sign in & security section of the Intuit Account manager, several verification options are available. Each one gives Intuit an additional way to confirm identity, and each one reduces the odds of a lockout becoming a crisis.
User ID. The sign-in identifier can be customized to something memorable. A user ID that is easy to recall reduces the first point of failure at the sign-in screen.
Email address. Keeping the email current means verification links and security notifications reach an inbox the user actually monitors. An outdated email address is one of the most common reasons account recovery stalls.
Phone number. A current phone number allows Intuit to send verification codes by text or voice call. This is the backbone of most two-step verification setups.
Passkeys. Passkeys let users sign in across multiple devices using biometric confirmation — face recognition, fingerprint, or screen lock — instead of typing a password. This method eliminates the risk of a forgotten password entirely.
Password. Longer passwords or passphrase strings provide better protection than short ones. Intuit’s guidance emphasizes length over complexity gimmicks.
Authenticator apps. Rather than relying on a text message for a one-time code, users can install an authenticator app — available on the iOS App Store and Google Play by searching “authenticator” — to generate time-based passcodes. This method avoids the risk of text-message interception or a phone being out of coverage range.
Turning On Two-Step Verification
The accepted solution for enabling two-step verification follows a defined sequence. After signing in to the Intuit Account, users navigate to Sign in & security, locate the 2-step verification section, and select Turn on, then Set up.
At that point, the user confirms the phone number on file and chooses a delivery method for the verification code: a standard six-digit text message or an automated voice call delivering the code in English. After selecting Continue, the user enters the code received, then enters the account password to confirm the change. A confirmation message indicates that two-step verification is active, and an email is sent documenting the security-preference update.
Switching to an Authenticator App
Users who prefer not to depend on text messages can switch to an authenticator app. In the same Sign in & security area, selecting Authenticator and then Set up authenticator app launches the guided setup. The user follows the on-screen prompts to link the app to the Intuit Account, after which the app generates one-time codes at sign-in.
Disabling Two-Step Verification
Turning the feature off is also a straightforward path. Under 2-step verification, toggling off the Use 2-step verification switch deactivates the feature. A confirmation message appears, and an email is sent noting the change. Disabling the feature does reduce account security, so it should generally be done only when changing devices or troubleshooting access problems.
When the Phone Number Itself Is the Problem
If the phone number on file is no longer accessible, the user cannot receive verification codes — which means they also cannot update the phone number through the normal flow. In that situation, the recovery path requires completing a Proof of identity form. The form asks the user to attach a copy of a government-issued ID — a driver’s license, state ID, passport, or a notarized document — and submit it for review. Once Intuit processes the request and updates the phone number, the user receives a notification and can sign back in.
This is the scenario every other verification method is meant to prevent. A passkey, an authenticator app, or a current backup email address can each provide an alternate route back in — but only if they were configured before the lockout happened.
The Bottom Line
The recurring pattern in community reports is the same: users set up their Intuit Account once, rarely revisit the security settings, and then discover during a sign-in failure that the phone number or email on file is years out of date. Configuring multiple verification methods ahead of time — and periodically confirming they are still accurate — remains the most reliable way to avoid an account-recovery process that can stall a business.
For broader QuickBooks troubleshooting resources, including account-access guidance and general help articles, the community knowledge base covers common sign-in and security scenarios.