Skip to content
TECHNOARTH Technology in practice.
Security

Two-factor authentication: what it is and how to turn it on

The layer of protection that stops account takeovers even when your password leaks. Which methods are safest and how to turn it on for Google, Microsoft, WhatsApp, Instagram and your company’s Microsoft 365.

Passwords leak: in data breaches, through phishing scams, or because they’re reused across services. Two-factor authentication (also called 2FA, MFA or two-step verification) requires a second proof of identity besides your password. With it, someone who learns your password still can’t get into your account.

In this article
  1. How it works
  2. Which method is safest
  3. How to turn it on for popular services
  4. At work: Microsoft 365
  5. Don’t lock yourself out
  6. Watch out for approval scams
  7. FAQ

How it works

A secure sign-in combines factors of different types:

  • Something you know: a password or PIN.
  • Something you have: your phone with an authenticator app, or a physical security key.
  • Something you are: a fingerprint or face recognition.

Which method is safest

MethodSecurityNotes
Passkey or physical security key (FIDO2)Very highPhishing-resistant: doesn’t work on fake sites
Authenticator app (code or number-matching approval)HighMicrosoft Authenticator, Google Authenticator and similar
SMSMediumVulnerable to SIM swapping
Email codeLowOnly as secure as the email account itself

Google (Gmail, YouTube, Drive)

  1. Go to myaccount.google.com and open Security.
  2. Under How you sign in to Google, turn on 2-Step Verification.
  3. Also add a passkey and an authenticator app as second methods.

Microsoft account (Outlook.com, Xbox, personal OneDrive)

  1. Go to account.microsoft.com and open Security.
  2. In the advanced options, turn on two-step verification and follow the wizard.

WhatsApp

  1. Open Settings › Account › Two-step verification.
  2. Create a 6-digit PIN and add a recovery email address.

Instagram and Facebook

  1. Open Accounts Center › Password and security › Two-factor authentication.
  2. Choose the account and pick the authentication app method.

At work: Microsoft 365

  • On plans without advanced features, keep Microsoft Entra ID security defaults turned on: they require MFA for all users and block legacy sign-in protocols.
  • On Business Premium, use Conditional Access to require MFA based on risk, location or device.
  • Administrator accounts should use the strongest methods (passkey or physical key), never SMS.

Don’t lock yourself out

  1. Save the backup codes the service generates when you turn it on, somewhere other than your phone (printed or in a password manager).
  2. Register two methods, for example an app and a passkey, or an app and a physical key.
  3. When you change phones, move your authenticator app before wiping the old device.

Watch out for approval scams

To protect your files against loss and ransomware as well, see the 3-2-1 backup rule.

FAQ

Are 2FA, MFA and two-step verification the same thing?

In practice, yes. MFA (multi-factor authentication) is the general term for using two or more factors; 2FA and two-step verification are the names most services use.

What if I lose my phone?

Use your backup codes or your second registered method to sign in, then remove the lost device from your account’s security settings.

What is a passkey?

A sign-in method that replaces your password with a credential stored on your device and unlocked by biometrics or PIN. It can’t be typed into fake sites, so it resists phishing.

Share

About the author

TECHNOARTH Editorial Team

The TECHNOARTH newsroom: technology tutorials, guides, comparisons and news produced with AI assistance and checked against manufacturers’ official sources.