What Is Two-Factor Authentication and How to Set It Up
Patrick Bushe
September 25, 2024 · 5 min read
Two-factor authentication, also called 2FA or two-step verification, means signing in takes two things: something you know, such as a password, and something you have, such as your phone or a security key. If someone steals your password, they still can't get in without the second factor.
The main methods, from weakest to strongest
- Text message codes: better than nothing, but codes can be intercepted or stolen through SIM swapping. See SIM swapping.
- Authenticator apps: apps such as Google Authenticator, Microsoft Authenticator or the one in your password manager generate a new six-digit code every 30 seconds.
- Push prompts: your phone asks you to approve a sign-in. Never approve one you didn't start.
- Security keys: a small USB or NFC device you tap to sign in. They can't be phished, because they check the website's real address.
- Passkeys: a newer way to sign in with your device's fingerprint, face or PIN, with no password at all. They also resist phishing.
Which accounts to protect first
- Email, because it can reset every other password.
- Your password manager.
- Banking and payments.
- Apple, Google or Microsoft accounts that back up your phone and photos.
- Social media and work accounts.
How to set it up
- Open the account's security settings and look for "Two-step verification," "2FA" or "Passkeys."
- Choose a method; an authenticator app or passkey is better than text messages.
- For an authenticator app, scan the QR code the site shows, then enter the code to confirm.
- Save the backup codes the site gives you somewhere safe, such as your password manager or on paper.
- Add a second method if offered, such as a backup security key.
Don't get locked out
- Keep backup codes where you can reach them if you lose your phone.
- Use an authenticator that can back up or sync, or register two devices.
- Before replacing your phone, move your authenticator to the new one.
Watch for tricks
Attackers may call or text pretending to be your bank and ask for a code. Real companies never ask you to read out a sign-in code. Also be careful with codes you copy: they sit on your clipboard, where some pages can read them. Clipboard Guard blocks websites from reading your clipboard.
See password managers and credential stuffing.