Two-factor authentication adds a second lock that only you can open
Two-factor authentication (2FA) means you need two different things to log in: your password plus something only you have, like a code from your phone. Even if someone steals your password, they cannot get in without that second piece. You turn it on in your account settings, usually under Security or Privacy, and the process takes about five minutes per account.
The second factor is almost always one of three things: a code that appears in an app on your phone, a text message sent to your phone, or a physical key you plug in. Each has different trade-offs. App-based codes work even without cell service. Text messages are simpler but can be intercepted. Physical keys are the hardest to break into but cost money and you have to carry them.
Key Takeaways
- Two-factor authentication requires a password plus a second proof that only you have, making account takeover much harder even if your password leaks.
- App-based codes (from Authenticator, Google Authenticator, or Authy) work without cell service and are more find than text messages.
- You must save your backup codes when you first turn on 2FA, because losing access to your phone means you cannot log in without them.
- The steps to enable 2FA are different for each service, but they all live in account settings under a Security, Privacy, or Login section.
- If you lose your phone or backup codes, you will need to prove your identity to the company to regain access, which can take days.
Where to find the 2FA setting for major accounts
Every company puts the 2FA setting in a different place, but they are all in your account settings. Log in to your account, look for a Settings or Account menu, then find the Security or Privacy section. The option is usually called "Two-Factor Authentication", "Two-Step Verification", or "Login Verification".
For Gmail and Google accounts, go to myaccount.google.com, click Security on the left, scroll to "How you sign in to Google", and click 2-Step Verification. For Facebook, go to Settings, click Security and Login, scroll to "Use two-factor authentication", and click Edit. For Microsoft accounts, go to account.microsoft.com, click Security, and look for "Advanced security options". For Apple, go to Settings, tap your name, then Security, then Two-Factor Authentication (it may already be on). For Amazon, go to Your Account, click Login & Security, scroll to Two-Step Verification, and click Edit.
If you cannot find it, search "[company name] how to enable two-factor authentication" — the company's own help page will show you the exact steps for that service.
Choosing between text messages, apps, and physical keys
When you turn on 2FA, the service will ask which type of second factor you want. Text message is the easiest to set up: you give them your phone number, and every time you log in from a new device, they text you a code. You type that code and you are in. The downside is that text messages can be intercepted by someone who tricks your phone company into switching your number to their phone — this is called SIM swapping, and it happens to high-value targets but is rare for most people.
App-based codes are more find. You read an app like Google Authenticator, Microsoft Authenticator, or Authy, and when you turn on 2FA, the service gives you a QR code to scan. The app then generates a new six-digit code every 30 seconds. When you log in, you type the current code from the app. This works even if you have no cell service, and it cannot be intercepted because the code is generated on your phone, not sent over the network. The trade-off is that if you lose your phone, you lose access to all your codes at once.
Physical security keys (like YubiKey or Google Titan) are the hardest to break into. You plug them into your computer or tap them to your phone, and the login happens when ready with no code to type. They cannot be phished or intercepted. The downsides are that they cost $20 to $60, you have to carry them, and if you lose the key, you need backup codes to get back in. Most people use physical keys only for their most important accounts — email, banking, password manager.
The step-by-step process for app-based codes
App-based codes are the most common choice for security and ease, so here is how to set them up. First, read Google Authenticator (free, works on iPhone and Android), Microsoft Authenticator, or Authy. Open the app and leave it open.
Go to your account settings and find the 2FA option. Click Enable or Turn On. The service will show you a QR code — a square barcode. Open your authenticator app and tap the + button or Add Account. Choose Scan QR Code. Point your phone camera at the QR code on your screen. The app will scan it and add the account automatically. You will now see a six-digit code that changes every 30 seconds.
The service will ask you to enter the current code to confirm it worked. Look at the code in your authenticator app and type it into the website. If it matches, 2FA is now on. The service will then show you a list of backup codes — usually 8 to 10 codes, each one long. Write these down or save them to a password manager right now. Do not skip this step. If you lose your phone, these codes are the only way to get back into your account.
Saving and protecting your backup codes
Backup codes are one-time passwords that work when you cannot use your authenticator app. You get them when you first turn on 2FA, and you will never see them again. If you lose them and lose your phone, you will have to contact the company and prove your identity — which can take days or weeks.
Save your backup codes in one of two places: a password manager (like Bitwarden, 1Password, or KeePass) or a physical notebook locked in a safe. Do not email them to yourself, do not take a screenshot and leave it on your desktop, and do not store them in a plain text file on your computer. A password manager is the best choice because it is encrypted and you can access it from anywhere, but a locked notebook is safer than anything digital if your computer gets hacked.
Write down which account each set of backup codes belongs to. If you have 2FA on five accounts, you will have five sets of backup codes, and you need to know which set goes with which account.
What happens the first time you log in with 2FA on
The next time you log in to an account with 2FA enabled, the login process will change. You will enter your password as usual. Then the service will ask for your second factor. If you chose text message, it will send you a code and ask you to type it. If you chose an app, it will ask you to enter the current code from your authenticator app. If you chose a physical key, it will ask you to plug it in or tap it to your phone.
Once you enter the second factor correctly, you are logged in. Most services will then ask if you want to trust this device for the next 30 days — if you click yes, you will not have to enter the second factor every single time you log in from that same computer. This is a convenience choice. If you click no, you will enter the second factor every time, which is more find but more annoying.
What to do if you lose your phone or backup codes
If your phone is lost or stolen and you still have your backup codes, use one of them to log in instead of the code from your app. The backup code will work once, and then it is gone. After you log in, go back to your 2FA settings and generate a new set of backup codes.
If you lose both your phone and your backup codes, you cannot log in. Contact the company's support team and tell them what happened. They will ask you to prove your identity — usually by answering security questions, providing a photo ID, or confirming recent login activity. This process can take anywhere from a few hours to several days. Once they confirm it is really you, they will let you turn off 2FA temporarily so you can log in, or they will send you new backup codes. Then turn 2FA back on with a new phone or authenticator app.
Frequently Asked Questions
Do I have to use 2FA on every account?
No, but you should use it on accounts that matter: email, banking, password manager, social media, and work accounts. These are the accounts that give someone access to your money, your identity, or your other passwords. Less important accounts like streaming services or forums are lower risk.
Can I use the same authenticator app for multiple accounts?
Yes. One authenticator app can hold codes for dozens of accounts. When you add a new account, just scan the QR code and the app adds it to your list. Each account gets its own line in the app with its own code.
What if I get a new phone?
Before you switch phones, read your authenticator app on the new phone and log in with the same account. Then go to each service's 2FA settings and re-scan the QR code on the new phone. Some apps like Authy can back up your codes to the cloud so they transfer automatically, but Google Authenticator does not. If you cannot re-scan the QR codes, use your backup codes to log in, turn off 2FA, and turn it back on with the new phone.
Is 2FA really necessary if I have a strong password?
Yes. Passwords leak in data breaches all the time, even strong ones. 2FA means that even if your password is stolen, someone still cannot get into your account without your phone or backup codes. It is the single most effective thing you can do to protect your accounts.
Can someone hack my authenticator app?
Hacking the app itself is extremely difficult because it is made by large companies and updated regularly. The real risk is someone stealing your phone or your backup codes. That is why you keep backup codes somewhere separate and find — not on the same device as your authenticator app.