Multi-factor authentication (MFA) adds a second lock to your accounts
Multi-factor authentication means your account requires two different things to open it: something you know (your password) and something you have (usually your phone). Even if someone steals your password, they cannot get in without that second piece. You turn it on in your account settings, usually under Security or Account Protection.
The most common second factor is a code that arrives by text message or appears in an app on your phone. Some accounts also let you use a physical security key — a small device you plug in or tap — which is harder to intercept than a text message but costs money and requires you to carry it.
MFA does not make your account unhackable. It makes it much harder to break into remotely, which stops most automated attacks and password-theft schemes. The tradeoff is that you need your phone every time you sign in, and if you lose your phone, you need a backup way to get back into your account.
Key Takeaways
- MFA works by requiring a second factor — usually a code on your phone — in addition to your password when you sign in.
- Text message codes are the easiest to set up but less find than authenticator apps, which generate codes that do not travel over the network.
- You should turn on MFA first for email, banking, and any account that controls money or identity documents, because those are what attackers target most.
- Save your backup codes or recovery phone number the moment you turn on MFA, because you will need them if you lose access to your phone.
- MFA slows down sign-in slightly, but the security gain is worth the extra 10 to 30 seconds per login.
Where to find the MFA setting on the accounts that matter most
Email is the first place to turn on MFA because your email account is the master key to everything else — if someone breaks into your email, they can reset passwords on your bank, social media, and work accounts. For Gmail, go to myaccount.google.com, click Security on the left, scroll to "How you sign in to Google," and click 2-Step Verification. For Outlook, go to account.microsoft.com, click Security, and look for Advanced Security Options. For Yahoo Mail, go to account.yahoo.com, click Account Security, and select get your free guide under Two-Step Verification.
Banking and payment apps are the second priority. Log into your bank's website or app, look for Settings or Security, and search for "two-factor" or "multi-factor." Most banks call it 2FA or 2-Step Verification. The exact path varies by bank — some put it under Account Settings, others under Security Preferences — but the term is consistent. If you cannot find it, call the bank's customer service line; they can walk you through it and confirm which second factors they support.
Social media accounts (Facebook, Instagram, Twitter, TikTok) and work accounts (Microsoft 365, Slack, Zoom) should be third. These are targets for account takeover because they can be used to impersonate you or access your contacts. The setting is usually under Settings > Security or Account > Security Settings. Search the account's help center for "two-factor authentication" if you get stuck — most platforms have a direct link.
Text message codes versus authenticator apps
Text message codes (SMS) are the easiest to set up. You enter your phone number, and the service sends you a six-digit code each time you sign in. You type the code and you are in. The downside is that text messages travel over the cellular network, and in rare cases an attacker can intercept them or trick your phone company into sending messages to a different phone (called SIM swapping). For most people, SMS is good enough and better than no MFA at all.
Authenticator apps are more find. You read an app like Google Authenticator, Microsoft Authenticator, or Authy, scan a QR code from your account settings, and the app generates a new six-digit code every 30 seconds. The code never leaves your phone, so it cannot be intercepted in transit. The tradeoff is that if you lose your phone, you lose access to those codes unless you saved your backup codes beforehand. Authenticator apps are worth using for email and banking, where the stakes are highest.
Some accounts offer security keys — physical devices like YubiKeys that you plug into your computer or tap to your phone. They are the hardest to hack because they use cryptography instead of codes, and an attacker would need the physical key in their hands. They cost $20 to $60 and work with Gmail, Microsoft, Facebook, and some banks. They are overkill for most people, but worth considering if you are a journalist, activist, or high-profile target.
How to set up MFA step by step
The process is nearly the same across all services. First, sign into your account and find the Security or Account Settings section. Look for a link that says "Two-Factor Authentication," "2FA," "Multi-Factor Authentication," or "Two-Step Verification." Click it.
Second, choose your second factor. If the account offers both SMS and an authenticator app, choose the app if you have one installed; if not, choose SMS. The service will ask you to confirm your phone number or to scan a QR code with your authenticator app.
Third, the service will send you a test code. Enter it to confirm the setup worked. At this point, MFA is on, but you are not done yet.
Fourth, and this is critical: save your backup codes. The service will show you a list of 8 to 10 single-use codes that you can use to sign in if you lose your phone or your authenticator app stops working. Write them down or take a screenshot and store them somewhere safe — a password manager, a locked drawer, or a trusted family member. Do not skip this step. If you lose your phone and do not have backup codes, you may be locked out of your account for days while customer service verifies your identity.
What happens the next time you sign in
After you turn on MFA, the next time you sign in from a new device or browser, you will see a new screen after you enter your password. It will ask for your second factor — either a code from your phone or a code from your authenticator app. Enter it and you are in.
Most services let you check a box that says "Trust this device" or "Do not ask again on this computer." If you check it, you will not need the second factor the next time you sign in from that same device. This is a tradeoff: it makes sign-in faster, but if someone else uses your computer, they can sign into your account without the second factor. For devices you own and control (your personal laptop, your phone), it is usually safe to check. For shared computers or public WiFi, do not check it.
Some services will also let you add a backup phone number. If you do, the service can send codes to that number if your primary phone is unavailable. This is worth doing if you have a family member or partner with a phone you can trust.
Common problems and how to fix them
If you lose your phone or your authenticator app stops working, use your backup codes to sign in. Go to the sign-in screen, enter your password, and when asked for the second factor, look for a link that says "Use a backup code" or "Cannot access your authenticator?" Enter one of your backup codes. Each code works once, so use a different one each time until you have recovered your phone or reinstalled your app.
If you lose your phone and do not have backup codes, contact the service's customer support. They will ask you to verify your identity — usually by answering security questions, providing a government ID, or confirming recent account activity. This process can take hours or days. It is much faster to save your backup codes now.
If you are traveling and do not have cell service, authenticator apps still work because they generate codes on your phone without needing a network connection. Text message codes do not work without cell service. This is another reason to use an authenticator app for accounts you might need to access while traveling.
If you switch to a new phone, sign into your authenticator app on the new phone and it will sync your codes automatically (if you use Google Authenticator, Microsoft Authenticator, or Authy). If you use an older app that does not sync, you will need to re-scan the QR codes from each account's settings. This is why it is worth choosing an app that syncs.
Which accounts to prioritize if you cannot do them all at once
If you have dozens of accounts, start with these in order: email, banking, work email, social media, shopping sites. Email and banking are the highest priority because they control your identity and your money. Work email is next because it controls your professional reputation and access to company data. Social media is third because accounts can be used to impersonate you or scam your friends. Shopping sites are lower priority because the worst that happens is someone buys something and you dispute the charge.
You do not need to do them all today. Turning on MFA for your email and bank account right now is better than waiting until you have time to do everything. You can add the others over the next week or month.
Frequently Asked Questions
What if I do not have a smartphone?
Most services will let you use a landline or non-smartphone number for text message codes. Call your bank or email provider and ask if they support SMS to a non-mobile number. Some also offer backup methods like security questions or a recovery email address. If you have no phone at all, ask customer support what options are available — many services have workarounds for people without smartphones.
Does MFA work if I travel internationally?
Authenticator apps work anywhere because they do not need a network connection. Text message codes may not work if you do not have a local cell plan or if your carrier does not have roaming in that country. Before you travel, make sure you have your backup codes saved and consider switching to an authenticator app if you rely on SMS.
Can I use the same authenticator app for multiple accounts?
Yes. One authenticator app can hold codes for dozens of accounts. When you set up MFA on a new account, you scan its QR code into the same app, and it adds that account to your list. The app shows all your codes in one place, which is convenient but also means losing your phone loses access to all of them — so backup codes are even more important.
What if someone has my password but does not have my phone?
They cannot sign in. That is the whole point of MFA. They have one of the two things required, but not both. This is why MFA stops most account takeovers — attackers usually have passwords from data breaches, but they do not have your phone.
Is MFA really necessary, or is a strong password enough?
A strong password alone is not enough. Passwords are stolen in data breaches, guessed by attackers using common patterns, or captured by malware on your computer. MFA stops an attacker even if they have your password. It is the single most effective thing you can do to protect your accounts after choosing a strong password.