Guide

How to use two-factor authentication

There is a second lock that keeps your account standing even if your password is stolen: two-factor authentication. Setting it up takes a few minutes, and the protection it gives is many times what a password offers alone.

Short answer

Two-factor authentication asks for a second proof after the password at sign-in: a code, an approval or a physical key. Even if your password leaks, getting into your account becomes far harder. The most practical starting point is using codes generated by an authenticator app.

Why a second step is needed

A password is “something you know”, and knowledge can be stolen: breaches, phishing pages and a glance over your shoulder are enough. Two-factor authentication adds “something you have” to the sign-in: your phone, your authenticator app, or a physical key.

Raising the attacker's task from stealing one piece of knowledge to seizing both the knowledge and the device leaves the great majority of takeover attempts fruitless from the start. That is why switching this on — for email, banking and social media accounts above all — is the single most effective security step available to you.

To picture how much that protects you, consider this: in large data breaches millions of passwords can be exposed at once, and yours may be circulating on a list. With two-factor authentication on, that list alone opens no door; the attempt fails at the second step, and most services will tell you a suspicious sign-in was tried.

The types: SMS, app, hardware key

Three methods are the most common. SMS code: a code arrives on your phone as you sign in. It is easy to set up but the weakest type, exposed to attacks such as SIM swapping and fake base stations. Even so, it is better than no verification at all.

Authenticator app: an app on your phone produces a new code every 30 seconds. Because the code does not travel over the internet, it is markedly safer than SMS and the best-balanced choice for most people. Some accounts also send an approval prompt to the phone instead of a code.

Hardware key: a small physical key that works over USB or contactlessly. It is the method most resistant to phishing, and worth considering for high-risk accounts.

How to set it up

The route is much the same on nearly every service: open the “Security” section of your account settings, find the “two-factor authentication” or “two-step verification” option and add your preferred method. If you choose an authenticator app, the service shows you a QR code, and scanning it with the app is all that is required.

Start with your email account, because password reset links for the other accounts go there. Then move on to banking, social media and cloud storage. Together with a strong password (see the strong password guide) this pair forms the foundation of account security.

While you are at it, fix one rule in place: verification codes are for you to enter and no one else. Anyone who telephones, introduces themselves as a bank or support agent, and asks for the code that has just arrived on your phone is a fraudster without exception; genuine institutions never ask for that code out loud.

Do not forget to keep the backup codes

During setup most services give you single-use backup codes. These codes are your insurance for getting into the account if your phone is lost or replaced. Print them and keep them somewhere safe, or save them in your password manager; leaving them as a screenshot in your gallery is not a good idea.

When changing phones, make a habit of using your authenticator app's account transfer feature and of seeing the codes work on the new device before resetting the old one.

Where you can, define more than one verification method on an account: the authenticator app as the main method, backup codes as the second safeguard. That way losing a single device does not shut you out entirely. Reviewing your methods once a year and clearing out entries that have gone stale, such as an old phone number, is the maintenance side of the same arrangement.

The limits worth knowing

Two-factor authentication is a strong lock, but it does not stop every attack. If you type both your password and your current code into a fake sign-in page, the attacker can use both immediately. So enter the code only on an official page or app that you opened yourself; if an approval prompt arrives that you were not expecting, reject it and change your password.

To recognise phishing traps, have a look at the phishing guide.

Checklist

  • Enable two-factor authentication on your email account
  • Install an authenticator app and add your accounts by QR code
  • Download the backup codes and store them somewhere safe
  • Turn the feature on for banking and social media accounts too
  • Make a habit of rejecting approval prompts you were not expecting

Frequently asked questions

Is verification by SMS enough?

It is far better than no verification at all; but moving to an authenticator app is recommended where possible. SMS is more vulnerable than the other methods to attacks such as SIM swapping.

If I lose my phone, will I be locked out?

If you kept the backup codes given at setup, you can sign in with those. Many services also offer identity-verified recovery processes, so keep your recovery email address and phone details current.

Do I have to enter a code at every sign-in?

Most services offer an option to remember devices you trust; if you enable it on your own computer, the code is only requested when signing in from a new device. Do not tick that option on shared devices.

Does an authenticator app need an internet connection?

No. The codes are generated on the device itself, based on the time, and work even in flight mode. This is one of its advantages over SMS.

This guide draws on the official security documentation of major technology platforms and on the multi-factor authentication advice of cyber security bodies.

First published: 2026-08-12Last reviewed: 2026-08-12Editorial status: working editionReport an error