Turn On Two-Factor Authentication
What it is
Two-factor authentication, also called multi-factor authentication or two-step verification, asks for a second proof of identity after your password. That second factor is usually a rotating code from an authenticator app, a tap on a prompt, or a physical security key you plug in or hold near your device.
The idea is that a password is something you know, and it can be stolen or guessed at a distance. A second factor is something you have, so an attacker needs your phone or your key in hand, not just a string of characters from a leaked database.
Time & frequency
About 5 minutes per account; do your email first, then work outward.
How to do it
- 1Start with your highest-value accounts. Email comes first, because it is the password-reset path for almost everything else, then banking, then anything holding money or personal data.
- 2Open that account's security settings. Look for a setting called 'Two-Factor Authentication', 'Two-Step Verification', or 'Multi-Factor Authentication'.
- 3Choose your second factor. An authenticator app that generates a rotating code, or a physical security key, is stronger than a code sent by text message. Pick the strongest option the account offers.
- 4Complete the setup. Scan the QR code with your authenticator app, or register your security key, then confirm by entering the first code it produces.
- 5Save the backup or recovery codes the service gives you somewhere offline. These let you back in if you lose your phone or key.
- 6Repeat everywhere. Turn it on for every account that offers it, not just the first one.
Why it works
A password on its own is a single wall. If someone leaks it in a breach, guesses it, or phishes it out of you, they walk straight in. A second factor adds a second wall the attacker does not have, such as a rotating code on your phone or a key in your pocket. Even holding your exact password, they cannot finish the login without also meeting the second step.
Not every second factor is equally strong. Codes sent by text message can be intercepted or redirected, while a code from an authenticator app or a physical security key stays in your possession. CISA lists the forms from strongest to weakest, with SMS and voice at the weak end, so where an account gives you a choice, pick the strongest form it supports.
Sources
- CISA, Secure Our World — Turn on MFA — a stolen password is not enough on its own: 'Even if an unauthorized user steals your password, they won't be able to meet the second step requirement to access your accounts.'
- CISA. Implementing Phishing-Resistant MFA (fact sheet) — 'not all forms of MFA are equally secure'; ranks forms strongest to weakest, with SMS/voice weakest.
Common mistakes
- Protecting only one account. Your email resets every other password, so if it is not covered, the rest are not really covered either. Cover email first.
- Choosing text-message codes when a stronger option exists. SMS is better than nothing, but it is the weakest form, so use an app or a security key when the account offers one.
- Not saving the recovery codes. Lose your phone with no backup codes and you can lock yourself out of your own account for good.
- Approving a prompt you did not start. If a login request pops up when you were not logging in, deny it. That is usually someone else trying a password they already have.
Practice it now
Lock down your email in five minutes
Your inbox is the master key to your other accounts, so protect it first.
- Open your email provider's security settings and find the two-factor or two-step option.
- Set up an authenticator app or a security key instead of text-message codes if both are offered.
- Save the recovery codes somewhere offline, then sign out and back in to confirm the second step now appears.
Related skills
Coherent Education
You just got the skill for free. The coached version is where it sticks.
seven live tracks, 58 coach-guided lessons, and games that train the skill — with a rep log so you can watch the work add up.
See the tracks