Recovery access should stay tightly controlled.

Authenticator sign-in requires the configured server-side secret and an active user account. Rotate the secret if a device is lost.