Resolving the "Verify it’s you" Login Challenge

Troubleshooting steps for Google Workspace Admin Console — Authentication issues

!

Overview

If a user (for example msrsandeep@youdomain.com) sees a "Verify it’s you" login challenge, follow the steps below in the Admin Console to remove outdated recovery/alternate emails and temporarily disable the login challenge.

1

Sign in to Admin Console

Go to admin.google.com and sign in using your Admin account.

2

Open the user's profile

Navigate to Users, then find and click the user (e.g., msr sandeep / msrsandeep@youdomain.com).

3

Remove alternate or recovery email

In User details → User information, remove any alternate/recovery/forwarding email addresses (for example, old addresses starting with @tab...). Click Save after removing them.

4

Disable login challenge temporarily

Inside the same user profile, open the Security tab. Scroll to Login Challenge and choose "Turn off login challenge for 10 minutes". Confirm and save changes.

This button starts an on-page countdown to help you track the 10-minute window — you still must perform UI actions in the Admin Console.

5

Retry login

Within the 10-minute window, go to the browser where the user is signing in (e.g., gmail.com) and try to sign in again. The user should be able to sign in without needing a verification code.

6

Re-enable security (optional)

After successful login, consider re-enabling the login challenge for the user: Admin Console → Security tab → Turn on login challenge.

Additional note

If the verification email continues to go to an unknown address (for example, an address starting with @tab...), an old recovery email is still present. Make sure to remove any outdated recovery emails as described in Step 3.