Passwords leak: in data breaches, through phishing scams, or because they’re reused across services. Two-factor authentication (also called 2FA, MFA or two-step verification) requires a second proof of identity besides your password. With it, someone who learns your password still can’t get into your account.
In this article
How it works
A secure sign-in combines factors of different types:
- Something you know: a password or PIN.
- Something you have: your phone with an authenticator app, or a physical security key.
- Something you are: a fingerprint or face recognition.
Which method is safest
| Method | Security | Notes |
|---|---|---|
| Passkey or physical security key (FIDO2) | Very high | Phishing-resistant: doesn’t work on fake sites |
| Authenticator app (code or number-matching approval) | High | Microsoft Authenticator, Google Authenticator and similar |
| SMS | Medium | Vulnerable to SIM swapping |
| Email code | Low | Only as secure as the email account itself |
How to turn it on for popular services
Google (Gmail, YouTube, Drive)
- Go to
myaccount.google.comand open Security. - Under How you sign in to Google, turn on 2-Step Verification.
- Also add a passkey and an authenticator app as second methods.
Microsoft account (Outlook.com, Xbox, personal OneDrive)
- Go to
account.microsoft.comand open Security. - In the advanced options, turn on two-step verification and follow the wizard.
- Open Settings › Account › Two-step verification.
- Create a 6-digit PIN and add a recovery email address.
Instagram and Facebook
- Open Accounts Center › Password and security › Two-factor authentication.
- Choose the account and pick the authentication app method.
At work: Microsoft 365
- On plans without advanced features, keep Microsoft Entra ID security defaults turned on: they require MFA for all users and block legacy sign-in protocols.
- On Business Premium, use Conditional Access to require MFA based on risk, location or device.
- Administrator accounts should use the strongest methods (passkey or physical key), never SMS.
Don’t lock yourself out
- Save the backup codes the service generates when you turn it on, somewhere other than your phone (printed or in a password manager).
- Register two methods, for example an app and a passkey, or an app and a physical key.
- When you change phones, move your authenticator app before wiping the old device.
Watch out for approval scams
To protect your files against loss and ransomware as well, see the 3-2-1 backup rule.
FAQ
Are 2FA, MFA and two-step verification the same thing?
In practice, yes. MFA (multi-factor authentication) is the general term for using two or more factors; 2FA and two-step verification are the names most services use.
What if I lose my phone?
Use your backup codes or your second registered method to sign in, then remove the lost device from your account’s security settings.
What is a passkey?
A sign-in method that replaces your password with a credential stored on your device and unlocked by biometrics or PIN. It can’t be typed into fake sites, so it resists phishing.