Skip to main content

Set Up 2FA or MFA: A Second Layer of Account Protection

Understand 2FA and MFA, choose a sign-in method, and save recovery codes before you need them. Start with your email account.

Set Up 2FA or MFA: A Second Layer of Account Protection

A 4-minute guide · Safety

What happe‍‍​​‍‍‍​‍​‍​​‍‍​​​‍​‍‍‍​‍​‍‍​‍​​‍​‍​‍‍‍​​​​​‍‍‍​‍​‍‍​‍​​​‍​​‍‍​​ns if someone learns your password? With an extra sign-in check turned on, knowing that password alone usually will not be enough to enter your account.

That extra protection is called two-factor authentication, or 2FA. It takes a little setup, but it can make a big difference. Start with your email account, since it often holds the links used to reset other passwords.

2FA and MFA: what is the difference?

Multifactor authentication (MFA) checks two or more different kinds of proof that you are the account owner:

  • Something you know: a password or PIN.
  • Something you have: a phone holding an authenticator or a physical security key.
  • Something you are: a fingerprint or face check.

2FA uses exactly two kinds of proof. It is a type of MFA. Entering two passwords does not count as two factors, because both are something you know. NIST's explanation of authentication factors

You may also see the label two-step verification in an account's settings. The available methods vary by service.

Which method should you choose?

MethodWhat you doWhat to know
Passkey or FIDO security keyUnlock your device, or connect or tap a registered keyResists fake login websites. Check the service's setup and recovery instructions.
Authenticator app codesEnter a changing code from an appAvoids text-message delivery risks, but a fake website can still trick you into entering the code.
App approvalApprove a sign-in request, sometimes by matching a numberApprove only requests you started. Number matching helps reduce accidental approvals.
Text message codesEnter a code sent to your phoneBetter than a password alone, but vulnerable to phone-number takeover and phishing.

Where offered, choose a passkey or a FIDO/WebAuthn security key for protection against phishing. An authenticator app is a useful option when those are unavailable. If text messages are your only option, turn them on rather than leaving the extra check off. CISA's guide to MFA methods

Some services send email codes. Their protection depends on keeping your email account secure too. Codes are not usually easy to guess; the danger is someone stealing, intercepting, or tricking you into sharing them.

Set it up on one account

Allow a few quiet minutes, with your phone nearby.

  1. Open the official app or your saved website bookmark. Avoid starting from a link in an unexpected message.
  2. Open account settings. Look for Security, Sign-in, or Privacy & Security, then Two-factor authentication, MFA, or Two-step verification. Names vary.
  3. Choose an available method. Follow the service's instructions for registering your phone, authenticator, passkey, or security key.
  4. Complete the verification. For an authenticator app, this commonly means scanning the setup QR code and entering the code the app generates. Keep that QR code and setup secret private.
  5. Save the recovery options. Do this before testing a fresh sign-in.
  6. Confirm it works. Keep your current session open while testing a new sign-in in another browser window. Check that the account settings show the protection is enabled.

If setting up an authenticator on the same phone, use the service's supported app-opening or manual setup option when you cannot scan the QR code.

Save a way back in

A lost phone should not mean a lost account. Services may offer backup codes, an additional security key, another trusted device, or a recovery process.

Backup codes are secret emergency sign-in codes. For example, Google lets you use one when your usual second step is unavailable; each code can be used only once. Google's backup-code instructions

Store them securely somewhere you can reach without the missing device or locked account. A printed copy in a locked drawer or safe can help. Do not keep your only copy inside the account it unlocks.

Before replacing or resetting your phone, follow your authenticator's transfer instructions and test access on the new device. Recovery and syncing work differently across apps.

Keep the extra check working for you

MFA reduces risk, but it does not stop every attack. A fake sign-in page can capture passwords and one-time codes. Passkeys and FIDO security keys help resist that trick by checking which website you are signing in to.

  • Never give sign-in or recovery codes to an unexpected caller or message sender.
  • Deny approval requests you did not start. Do not approve repeated prompts just to silence them.
  • If unexpected requests keep arriving, open the real service yourself, review account activity, and change your password if compromise is suspected.

Today's task: protect your email account, confirm the new sign-in method works, and save a recovery option.

Keep learning