Two-factor authentication adds a second security check when you sign in
Two-factor authentication (often called 2FA) means you need two different things to prove you are you when logging into an account. The first is what you know — your password. The second is something you have or something you are — usually a code from your phone, a physical security key, or your fingerprint.
Without two-factor authentication, a stolen password is all someone needs to get into your account. With it, they would also need access to that second factor. This stops most account takeovers even when your password leaks in a data breach.
Most major services now offer two-factor authentication, and many let you choose which type of second factor works best for you. The setup takes a few minutes, and logging in takes a few seconds longer each time.
Key Takeaways
- Two-factor authentication requires a password plus a second proof of identity, such as a code sent to your phone or generated by an app.
- The most common second factors are text message codes, authenticator apps, and physical security keys, each with different strengths and weaknesses.
- Turning on two-factor authentication for email and financial accounts protects you even if your password is stolen or guessed.
- You should save backup codes when you set up two-factor authentication, because losing access to your second factor can lock you out of your account.
The three main types of second factors
Text message codes (SMS) are the easiest to set up. When you log in, the service sends a six-digit code to your phone via text. You type that code into the login screen. This works on any phone with texting, and you do not need to install anything. The downside is that text messages can be intercepted in rare cases, and if someone gains control of your phone number, they can receive your codes.
Authenticator apps like Google Authenticator, Microsoft Authenticator, or Authy generate a new code every 30 seconds on your phone. You open the app and type the current code into the login screen. These are more secure than text messages because the codes are generated on your phone, not sent over the network. The trade-off is that you need to install the app and keep your phone with you when you log in.
Physical security keys are small devices (about the size of a USB drive or a car key) that you plug into your computer or tap to your phone to prove you are logging in. They are the most secure option because they cannot be phished or intercepted. They cost money and you can lose them, so many people keep a backup key in a safe place.
Some services also offer biometric authentication — your fingerprint or face — as a second factor. This is convenient because you always have your fingerprint with you, but it only works on devices with a fingerprint or face scanner.
How to turn on two-factor authentication
The exact steps vary by service, but the process is always similar. First, go to your account settings or security settings. Look for a section called "Two-Factor Authentication," "Two-Step Verification," "Security," or "Sign-In & Security." Click the option to turn it on.
The service will ask you to choose a second factor type. If you choose an authenticator app, you will scan a QR code with your phone, and the app will start generating codes. If you choose text message, the service will confirm your phone number. If you choose a security key, you will plug it in or tap it to your phone to test it.
After you set up your second factor, the service will show you a list of backup codes — usually 8 to 10 one-time codes you can use if you lose access to your phone or key. Write these down or save them in a password manager. Store them somewhere safe and separate from your phone. If you lose your second factor and do not have backup codes, you may not be able to get back into your account.
Once two-factor authentication is on, you will be asked for your second factor every time you log in from a new device. Some services let you trust a device for 30 days so you do not have to enter the code every single time on your home computer.
Which accounts should have two-factor authentication
Turn on two-factor authentication first for accounts that protect other accounts or contain sensitive information. Your email is the most important because most services use email to reset your password. If someone takes over your email, they can reset passwords for your bank, social media, and work accounts. Set up two-factor authentication on email before anything else.
After email, prioritize financial accounts — your bank, credit card, investment accounts, and payment services like PayPal or Venmo. These accounts directly control your money, so the extra security is worth the few extra seconds at login.
Then add two-factor authentication to social media, work accounts, and any service that stores personal information like your address or phone number. You do not need it on every account you have, but the more accounts you protect, the safer you are.
What to do if you lose access to your second factor
If you lose your phone or break your security key, you will not be able to log in unless you have backup codes. This is why saving those codes is so important. If you have them, you can use one code to log in, then go to your account settings and set up a new second factor.
If you do not have backup codes and cannot access your second factor, you will need to prove your identity to the service another way. Most services have a recovery process where you answer security questions, provide a photo ID, or verify ownership of your email or phone number. This process can take days or weeks, so prevention is much easier than recovery.
If you are locked out of an account and cannot recover it, contact the service's support team. They can sometimes help, but there is no may provide. This is another reason to keep backup codes in a safe place.
Common mistakes to avoid
Do not use the same authenticator app on multiple devices without a backup plan. If that device breaks, you lose access to all your codes. Services like Authy and Microsoft Authenticator let you back up your codes to the cloud so you can restore them on a new phone, but Google Authenticator does not. If you use Google Authenticator, save your backup codes.
Do not ignore the backup codes. Many people set up two-factor authentication and throw away the backup codes, then panic when they lose their phone. Those codes are your safety net.
Do not assume text message is as secure as an authenticator app. Text messages can be intercepted, and phone number takeovers do happen. If the service offers an authenticator app or security key, use that instead of SMS.
Do not set up two-factor authentication on an account and then forget which second factor you chose. Write it down or keep a note in your password manager so you remember whether you used an app, a key, or a text message.
Frequently Asked Questions
Can someone hack my account if I have two-factor authentication on?
It is much harder, but not impossible. Two-factor authentication stops most attacks because a hacker would need both your password and access to your second factor. However, if a hacker tricks you into giving them a code (called phishing), or if they take over your phone number, they could still get in. Using a security key instead of text messages makes this much less likely.
What happens if I lose my phone and do not have backup codes?
You will be locked out of your account. You will need to contact the service and prove your identity through their recovery process, which can take days or weeks. This is why backup codes are so important — save them the moment you set up two-factor authentication.
Do I need two-factor authentication on every account I have?
No, but you should use it on accounts that matter most: email, bank, credit cards, and work accounts. You can skip it on accounts with no sensitive information, though there is no harm in turning it on everywhere if you do not mind the extra step at login.
Is an authenticator app safer than a text message code?
Yes. Authenticator apps generate codes on your phone that cannot be intercepted, while text messages travel over the network and can theoretically be intercepted. A security key is even safer because it cannot be phished. If a service offers all three, use a security key; if not, use an authenticator app.
Can I use two-factor authentication on multiple devices?
It depends on the type. Authenticator apps can be installed on multiple phones, but you will need to set them up separately on each device. Security keys work on any device that supports them. Text messages go to one phone number. If you want to log in from multiple devices, an authenticator app or security key is more flexible than SMS.