Two-factor authentication adds a second lock to your accounts
Two-factor authentication (often called 2FA) means you need two different things to log in: your password, plus a second proof that you're really you. That second proof is usually a code from your phone, a fingerprint scan, or a security key. Even if someone steals your password, they can't get into your account without that second factor.
The accounts most worth protecting are email, banking, and social media — because email is the master key to resetting passwords on everything else. If someone takes over your email, they can reset your bank password, your social media, your work account. Start there, then work outward to other accounts you use regularly.
The setup takes five to ten minutes per account. You do it once, and then every time you log in from a new device, you'll enter a code or approve a prompt. It's a small friction that stops most attackers cold.
Key Takeaways
- Email is the priority because resetting your password on any other account usually goes through email first.
- Most phones can generate codes through an authenticator app like Google Authenticator or Authy, which works even without cell service.
- Text message codes (SMS) are better than nothing but less secure than an authenticator app, because text messages can be intercepted.
- Save your backup codes when the account offers them — they let you log in if you lose access to your phone.
- You can turn on 2FA for most major accounts in their security settings, usually under "Security" or "Account Protection".
Where to find 2FA settings on the accounts you use most
The path to 2FA settings varies by service, but they're always in your account settings, not in the main app menu. Here's where to look on the biggest platforms:
Gmail and Google accounts: Go to myaccount.google.com, click "Security" on the left, scroll to "How you sign in to Google," and click "2-Step Verification." Google calls it 2-Step instead of 2FA, but it's the same thing.
Microsoft accounts (Outlook, OneDrive, Xbox): Go to account.microsoft.com, click "Security" on the left, then "Advanced security options." Look for "Two-step verification" and click "Set up two-step verification."
Facebook: Click the menu icon (three horizontal lines) in the bottom right, go to "Settings & privacy," then "Settings." Click "Security and login" on the left, scroll to "Two-factor authentication," and click "Edit."
Apple ID (iCloud, App Store, Apple Music): Go to appleid.apple.com, click "Security" on the left, and look for "Two-factor authentication." If it's not already on, click "Enable Two-Factor Authentication."
Amazon: Go to amazon.com, click your account name in the top right, select "Login & security," scroll to "Two-Step Verification (2SV)," and click "Edit."
Banking apps: Most banks have 2FA built into their security settings. Look for "Security," "Account Protection," or "Login Settings" in your app's menu. If you can't find it, call the bank's customer service line — they can walk you through it.
Choosing between authenticator apps, text codes, and security keys
Most accounts offer you a choice of how to receive your second factor. Each has a different balance of security and convenience.
Authenticator apps (Google Authenticator, Microsoft Authenticator, Authy) are the best choice for most people. You install the app on your phone, and when you log in, the app generates a six-digit code that changes every 30 seconds. The code works even if you have no cell service. The app is free. The downside: if you lose your phone and don't have backup codes saved, you're locked out until you contact support.
Text message codes (SMS) are easier to set up — the account just needs your phone number — but less secure. Text messages can be intercepted by someone with access to your phone line or your carrier's systems. Use SMS only if the account doesn't offer an authenticator app, or as a backup method alongside an app.
Security keys (like YubiKey or Google Titan) are the most secure option. They're small physical devices you plug into your computer or tap to your phone. An attacker can't intercept or guess a security key. The downside: they cost money (usually $20 to $60), and you need to carry them. Use security keys for your most critical accounts — email, banking, work — if you're willing to spend the money.
Most accounts let you set up more than one method. A good setup is: authenticator app as your main method, text message as a backup, and security key if you have one.
What to do with backup codes
When you turn on 2FA, the account usually gives you a list of backup codes — usually 8 to 10 single-use codes that work if you can't access your authenticator app or phone. Write them down or take a screenshot, and store them somewhere safe and separate from your phone. A password manager like Bitwarden or 1Password can store them. A notebook in a drawer at home works too. Do not email them to yourself or leave them in a cloud folder that uses the same password as the account you're protecting.
If you ever use a backup code, write down which one you used so you know how many you have left. When you're down to your last two or three, log back into that account and generate a new set of backup codes.
What happens the first time you log in with 2FA turned on
The first time you log in after turning on 2FA, you'll enter your password as usual. Then the account will ask for your second factor. If you chose an authenticator app, open the app, find the entry for that account, and enter the six-digit code. If you chose text message, wait for the text to arrive and enter the code from the message. If you chose a security key, plug it in or tap it to your phone when prompted.
On your own device — the phone or computer you use every day — most accounts will ask if you want to "trust this device" or "remember this device for 30 days." Clicking yes means you won't have to enter the second factor every single time you log in from that device. It's safe to click yes on devices you own and use regularly. Don't click yes on a public computer or a friend's device.
Every time you log in from a new device — a new phone, a new computer, a browser you've never used before — you'll need to enter the second factor again. This is the security working as intended.
Turning on 2FA without losing access to your account
The most common mistake is setting up 2FA, then losing the phone with the authenticator app and not having the backup codes written down. You end up locked out of your own account. Here's how to avoid it:
Before you turn on 2FA, make sure you have a way to receive codes. If you're using an authenticator app, install it first and make sure it works. If you're using text message, make sure your phone number is current in your account settings. Then turn on 2FA. The account will show you the backup codes — screenshot them or write them down before you click "Done" or "Confirm." Store the backup codes somewhere you can find them later, separate from your phone.
If you change phones, most authenticator apps let you transfer your accounts to the new phone before you wipe the old one. Open the app on your new phone, look for "Transfer accounts" or "Import," and follow the prompts. If the app doesn't have a transfer option, you can log into the account from your new phone and re-add it to the authenticator app — the account will generate a new QR code to scan.
If you lose your phone and don't have the backup codes, contact the account's support team immediately. You'll have to prove you own the account — usually by answering security questions or providing a photo ID. It takes longer than using a backup code, but you can still get back in.
Which accounts to prioritize if you're starting out
If you're new to 2FA and don't want to set it up everywhere at once, start with these in order:
Email first. Your email is the key to resetting passwords on every other account. If someone takes over your email, they can reset your bank password, your social media, your work account. Set up 2FA on your primary email address before anything else.
Banking and money next. Your bank account, PayPal, Venmo, or other payment apps. These accounts can directly move your money. 2FA here stops someone from draining your account even if they have your password.
Social media and work third. Facebook, Instagram, Twitter, LinkedIn, and your work email or Slack. These accounts can damage your reputation or give an attacker access to work systems and files.
Everything else after that. Once you've protected email, money, and work, you can add 2FA to shopping accounts, streaming services, and other sites at your own pace. The risk is lower, but the protection is still worth it.
Frequently Asked Questions
What if I don't have a smartphone?
You can use text message codes instead of an authenticator app — the account will text you a code each time you log in. It's less secure than an app, but better than no 2FA. Some banks and email providers also offer backup phone numbers or security questions as a second factor. Call the account's support line to ask what options are available without a smartphone.
Can I use 2FA on a tablet or computer instead of a phone?
Yes. Authenticator apps work on tablets and computers. If you use a computer as your main device, you can install an authenticator app there. The tradeoff is that if someone gains access to that computer, they can see your codes. A phone kept separate from your computer is more secure.
What if I get a new phone and can't access my authenticator app?
Use your backup codes to log in. Once you're in, remove the old phone from your authenticator app settings and add your new phone. If you don't have backup codes, contact the account's support team and explain that you've changed phones. They can verify your identity and help you regain access.
Does 2FA slow down my login every time?
The first time you log in from a device, yes — you'll need to enter a code, which takes 10 to 30 seconds. Most accounts let you check a box to "trust this device," so you won't need the code again for 30 days or until you log out. On devices you use every day, you'll only enter the code once a month or less.
Can someone use my backup codes to get into my account?
Only if they have both your password and your backup codes. That's why it's important to store backup codes separately from your password — don't write them in the same notebook or save them in the same file. If someone has your password but not your backup codes, they still can't log in.