How-To Guides

How to Set Up Two-Factor Authentication

To set up two-factor authentication, open the account’s Security settings, choose Two-Factor or Two-Step Verification, and pick an authenticator app or a passkey rather than SMS. Scan the QR code with the app, type the six-digit code back to confirm the link, then save the backup recovery codes somewhere separate from your password. A passkey or a hardware security key is the strongest option in 2026, an authenticator app is the next best, and SMS is a last resort.

2factors needed: your password plus one more proof
30 sechow often an authenticator code refreshes
800M+Google accounts now using a passkey (2026)
SMSthe weakest method, exposed to SIM swapping

Why Turn On Two-Factor Authentication?

Two-factor authentication (2FA) adds a second proof of identity beyond your password, so a stolen password alone no longer opens the account. The reasons below explain why a second factor is worth the one-time setup.

  • A stolen password stops being enough. An attacker who has your password still cannot pass the second factor without your app, key, or device.
  • Reused-password attacks fail. Passwords leaked in one breach cannot unlock a 2FA-protected account on their own.
  • Phishing gets harder. A passkey or security key is bound to the real site and refuses to authenticate on a fake one.
  • You keep a way back in. Backup recovery codes let you regain access if the second-factor device is lost.

Google has reported that adding an on-device prompt as a second factor blocked every automated bot attack and the large majority of targeted attacks in its testing. Microsoft has likewise found that turning on a second factor stops the great majority of automated account-takeover attempts. A second factor turns one barrier into two independent ones.

Which 2FA Method Should You Choose?

Pick the strongest method the account offers: a passkey or security key first, an authenticator app next, and SMS only as a last resort. The three options below cover almost every account.

SMS text code
A six-digit code texted to your phone number. It is the easiest to set up and works on almost any phone, but the carrier network can be manipulated, so it is the weakest method. Best for: accounts that offer no other second factor, where any 2FA beats none.
Authenticator app (TOTP)
A free app such as Google Authenticator, Microsoft Authenticator, or Authy that generates a code every 30 seconds on your device. The code never travels over a network, so a SIM swap cannot intercept it. Best for: the everyday default on every account that supports it.
Passkey or security key
A passkey (Face ID, fingerprint, or Windows Hello) or a FIDO2 hardware key such as a YubiKey, using public-key cryptography bound to the real site. Both resist phishing entirely. Best for: email, banking, and other high-value accounts.

A passkey can replace both the password and a separate second factor on sites that support it, which is why Apple, Google, and Microsoft are pushing it as the default. Google reports more than 800 million accounts already use a passkey, and NIST now recognizes synced passkeys as phishing-resistant authentication. Where a passkey is offered, it is the strongest choice; where it is not, an authenticator app is the one to use. The wider picture is covered in multi-factor authentication.

How Do You Enable 2FA and Scan the QR Code?

Turn on 2FA in the account’s Security settings, then scan the QR code with your authenticator app to link the two. The steps below apply to most services, with only minor wording differences.

Enable 2FA and Scan the QR Code - How to Set Up Two-Factor Authentication
  • Open Security settings. Sign in to the account and go to Settings, then Security, Account, or Login.
  • Find the 2FA option. Look for Two-Factor Authentication, Two-Step Verification, or 2FA, then choose Authenticator app (or Passkey, if you prefer the stronger route).
  • Add the account in your app. Open the authenticator app and tap Add account or the plus icon.
  • Scan the QR code. Point the phone camera at the QR code on screen to import the secret automatically.
  • Confirm a code. Type the six-digit code the app shows back into the website to prove the link works.
  • Save the change. Confirm, which switches the account to ask for the code at each new sign-in.

If a service shows a text setup key instead of a QR code, type that key into the app by hand to add the account. The code then refreshes every 30 seconds, and you enter the current one whenever the site asks.

How Do You Save the Backup Recovery Codes?

Backup codes are one-time recovery codes that restore access when the authenticator device is lost, so save them during setup, not later. The steps below store them safely.

Save Backup Codes - How to Set Up Two-Factor Authentication
  • Open the codes. On the 2FA page select Get backup codes or View recovery codes.
  • Copy the full set. Most services show ten one-time codes; capture all of them.
  • Store them apart from the password. Save them in a password manager note or print them and keep the paper offline.
  • Never keep them beside the password. One breach would otherwise expose both factors at once.
  • Regenerate when needed. If a code is used or the list is exposed, generate a fresh set, which voids the old codes.

Each backup code works once. A saved set is what lets you sign in if the phone running your authenticator is lost, stolen, or reset, so skipping this step is the most common way people lock themselves out. A password manager can hold both the codes and your password securely.

How Do You Add a Passkey or Security Key?

A passkey or hardware security key adds phishing-resistant 2FA using public-key cryptography bound to the real website. The steps below register one as either your main login or a strong second factor.

  1. Get a FIDO2 hardware key such as a YubiKey or a Google Titan key, or use the built-in passkey on your phone or laptop.
  2. Open the account Security settings and select Add passkey or Add security key.
  3. Follow the prompt: touch the hardware key’s sensor, or approve the passkey with your fingerprint or face unlock.
  4. Name the key so multiple registered keys stay easy to tell apart.
  5. Register a second backup key and store it separately, so a lost key does not lock you out.

A passkey stores its private key in the device’s secure hardware and syncs through the platform account, such as iCloud Keychain or a Google account, so a new phone keeps working. Both a passkey and a FIDO2 key refuse to authenticate on a fraudulent domain, which is why they stop phishing that an app code cannot.

Why Avoid SMS Codes Where Possible?

SMS is the weakest second factor because the carrier network around your phone number can be manipulated. The risks below explain why an authenticator app, passkey, or key is preferred.

An authenticator app or passkey is far safer than SMS, and you must save the backup codes. A SIM-swap attack moves your phone number to an attacker’s SIM, after which every SMS code arrives on their device, and carrier signaling flaws can route texts the same way. An authenticator app generates codes on your own device with nothing sent over the network, and a passkey or security key cannot be redirected at all. Whichever factor you pick, the saved backup recovery codes are the only thing that gets you back in when the device is lost.

SMS still beats no second factor, so enable it on any account that offers nothing else. Where you can, also turn off SMS as a recovery fallback once a stronger factor is in place, since an attacker who hijacks your number could otherwise use the fallback to bypass it.

Second-Factor Strength Comparison

The table ranks the common second factors by how well they resist phishing, whether they work offline, and their main weakness.

Second FactorPhishing ResistanceWorks OfflineMain Weakness
Security key (FIDO2)HighestYesRequires carrying the hardware key
PasskeyHighestYesTied to a platform account for sync
Authenticator app (TOTP)ModerateYesCodes can be entered on a phishing page
Push notificationModerateNoUser can approve a fraudulent prompt
SMS codeLowNoSIM swapping and network interception
Email codeLowNoA compromised inbox exposes the code

Common 2FA Mistakes to Avoid

A few errors weaken two-factor authentication or risk a lockout. The mistakes below recur when people turn on 2FA.

  • Skipping the backup codes. A lost phone with no saved codes can lock the account for good.
  • Storing codes with the password. Keeping backup codes beside the password lets one breach defeat both factors.
  • Relying only on SMS. SMS exposes the account to SIM swapping; an authenticator app, passkey, or key avoids it.
  • Registering only one security key. A single key with no backup means a lost key blocks access.
  • Reusing a weak password. 2FA protects the second barrier, so the first still needs to be a strong, unique password.

Last Thoughts on Setting Up Two-Factor Authentication

Setting up two-factor authentication is a one-time job that turns a single password barrier into two independent ones, blocking access even after a password leak. Open the account’s Security settings, choose an authenticator app or a passkey over SMS, scan the QR code, confirm a code, and save the backup recovery codes somewhere separate from your password. A passkey or a FIDO2 security key resists phishing entirely and is the direction Apple, Google, and Microsoft are all pushing in 2026, while an authenticator app is the next best on any account that does not yet offer one.

Because the password is still the first factor, 2FA works best alongside a strong, unique password kept in a password manager, which can store the backup codes too. Set the same protection on every account that matters, starting with your email, since that inbox can reset the others. For more step-by-step security and setup guides, see the PC tutorials hub.

Key Takeaways:

  • Turn on 2FA in the account’s Security settings, then scan the QR code to link an authenticator app.
  • Prefer a passkey or a security key first, an authenticator app next, and SMS only as a last resort.
  • An authenticator app generates codes on your device, so a SIM swap cannot intercept them.
  • Always save the one-time backup recovery codes, and store them apart from your password.
  • Register a backup passkey or second security key so a lost device does not lock you out.
  • Pair 2FA with a strong, unique password, because the password is still the first factor.

Frequently Asked Questions (FAQs)

How do I set up two-factor authentication?

Open the account’s Security or Login settings, choose Two-Factor Authentication or Two-Step Verification, and pick an authenticator app or a passkey rather than SMS. Scan the QR code with the app, type the six-digit code back to confirm, then save the backup recovery codes somewhere safe.

Which 2FA method should I choose?

Choose a passkey or a hardware security key where the site supports one, because both resist phishing. An authenticator app is the next best and works on almost every account. Use SMS only when no other option is offered, since it is the weakest method.

Is an authenticator app better than SMS for 2FA?

Yes. An authenticator app generates codes on your device and sends nothing over the carrier network, so a SIM-swap attack cannot intercept them. SMS codes can be redirected to an attacker’s SIM or read through carrier network flaws.

What are 2FA backup codes and why save them?

Backup codes are one-time recovery codes a service shows when you turn on 2FA. Each works once and lets you sign in if you lose the phone running your authenticator. Save them in a password manager note or print them, and never store them beside your password.

What happens if I lose my phone with the authenticator app?

Use a saved backup code to sign in, then register the authenticator on a new phone. If you also registered a passkey or a second security key, you can sign in with that instead. Without any backup, recovery depends on the service and can take days.

Should I set up a passkey instead of 2FA?

A passkey is a phishing-resistant login that can replace both the password and a separate second factor on sites that support it. Where a passkey is offered, it is the strongest choice. On sites that do not yet offer one, turn on 2FA with an authenticator app.

Nizam Ud Deen

Muhammad Nizam Ud Deen Usman is the founder of theCoreiTech and the author of The Local SEO Cosmos. Nizam works as an SEO consultant and content strategy expert with more than a decade of experience in digital marketing and IT, and he also founded ORM Digital Solutions, a digital agency serving medium and large businesses. He holds a degree from the University of Education, Lahore (Multan Campus), and was listed among the top 20 SEO experts in Pakistan in 2024. Nizam started theCoreiTech in 2012 to make computers easier to understand and use for everyone. Connect with Nizam on LinkedIn (seoobserver), X (@SEO_Observer), or at nizamuddeen.com.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button