1. Check the accounts that can lock you out
Start with your primary email. It is often the recovery channel for banking, cloud storage, work tools, social accounts, and the app store itself. If email access depends on an SMS sent to a SIM that is unavailable abroad, every downstream recovery path becomes more fragile.
Do not replace everything in one sitting. Make a short list of critical accounts, change one account at a time, and complete a real sign-in before moving to the next. Keep the old authenticator and old recovery method until the replacement has been tested.
- List the primary email, password manager, Apple or Google account, banks, work identity, mobile carrier, and any service needed during the trip.
- Mark the accounts whose only second factor is a text message or call to one phone number.
- Add a passkey or hardware security key where the service and your recovery setup support it.
- For accounts without a phishing-resistant option, add a standard authenticator code rather than relying only on SMS.
- Generate fresh recovery codes and keep them somewhere separate from the password and the only phone.
- Confirm that the account has a second, independent recovery method. More copies of the same SIM-dependent method do not add much resilience.
- Turn on airplane mode and verify that the authenticator still produces current codes. Then reconnect and complete a real sign-in.