9sBlog

How to set up two-factor authentication (2FA)

Two-factor authentication blocks most account takeovers even if your password leaks. Learn how to turn on 2FA for Google, Microsoft, and more.

Lines of code on a computer screen.

A leaked or guessed password is only dangerous when it is the one thing standing between an attacker and your account. Two-factor authentication (2FA) adds a second check, so a stolen password alone is not enough to get in. This guide explains what 2FA is, which methods are strongest, and exactly where to switch it on for your Google, Microsoft, and other accounts.

What 2FA is, and why it stops most takeovers

Two-factor authentication, also called two-step verification or multi-factor authentication (MFA), means proving who you are with two different things: something you know (your password) and something you have (a code from an app, a tap on your phone, or a security key). The U.S. Cybersecurity and Infrastructure Security Agency runs a public campaign called “More than a Password” for exactly this reason, because a password on its own is a single point of failure.

Most account takeovers begin with a password that leaked in a breach or was captured by a fake login page. When a second factor is required, that stolen password no longer opens the door, because the attacker does not also have your phone or your key. CISA’s position is blunt and worth remembering: any MFA is better than no MFA.

The methods, ranked from strongest to weakest

Not all second factors are equal. A code texted to you (SMS) is the weakest common option: attackers can intercept it, or trick your carrier into moving your number to a SIM they control (a “SIM swap”), and a convincing fake login page can simply ask you to type the code straight to them. An authenticator app is much better, because the code lives on your device and never travels over the phone network. Stronger still are phishing-resistant methods, a passkey or a hardware security key built on the FIDO standard, which are tied to the real website and will not work on a lookalike page.

CISA recommends hardware or FIDO-based options for the greatest protection, calls app-based codes a good option, and says SMS should be a last resort, a ranking it lays out in its guidance on phishing-resistant MFA. Even so, SMS 2FA is far better than no second factor at all.

MethodSecurityConvenienceNotes
Passkey / FIDO security keyStrongest (phishing-resistant)High once set upTied to the real site; a fake page can’t use it
Authenticator app (one-time codes)StrongHigh6-digit code refreshes about every 30 seconds; works offline
Push prompt (e.g. a Google prompt)StrongVery highYou approve or deny the sign-in on your phone
Backup / recovery codesStrong, one-timeLowFor when you lose your main method; store them safely
SMS or voice codeWeakest, but better than nothingHighVulnerable to SIM swaps and interception

Turn on 2-Step Verification for a Google Account

Open your Google Account, go to Security, and under “How you sign in to Google” select 2-Step Verification, then follow the on-screen steps. Google lets you add several second steps, including a Google prompt on your phone, Google Authenticator or another authenticator app, a hardware security key, a passkey, and a set of backup codes; a text or voice code is offered too. Choose an authenticator app or a prompt as your main method rather than relying only on text messages. The full walkthrough is on Google’s 2-Step Verification help page, which also warns you never to share a verification code with anyone.

Turn on two-step verification for a Microsoft account

Sign in at account.microsoft.com/security, open the Security section, and choose “Manage how I sign in.” Under the additional-security and two-step verification settings, turn it on and follow the prompts. Microsoft’s recommended second factor is the Microsoft Authenticator app; during setup you scan a QR code so the app is tied to your own device. The steps are documented in Microsoft’s two-step verification guide.

Where the setting lives on other services

The wording differs from site to site, but almost every major service keeps 2FA in the same neighborhood: your account’s security or login settings. Look for a menu named Security, Password & security, Login & security, or Sign-in, and then an option that mentions two-factor, two-step, or MFA. If you cannot find it, search the service’s own help center for “two-factor” rather than guessing.

ServiceWhere the setting livesWhat it’s called there
Google AccountSecurity > How you sign in to Google2-Step Verification
Microsoft accountaccount.microsoft.com > SecurityTwo-step verification
Apple AccountSettings > your name > Sign-In & SecurityTwo-Factor Authentication
Most other sitesSettings > Security or LoginTwo-factor / two-step / MFA

Save your backup and recovery codes

When you switch 2FA on, the service offers a way back in for the day you lose your phone: Google gives you a set of one-time backup codes, and Microsoft gives you a recovery code. Save these somewhere you can reach without the account itself, such as a password manager or a printout kept somewhere safe, and not in the same email inbox you are protecting. Microsoft’s recovery code is not case-sensitive and does not need spaces or dashes when you enter it; you can generate one from your account’s advanced security options, as described in how to get a Microsoft account recovery code. Treat these codes like spare keys, because anyone who has them can walk straight past your second factor.

The next step up is a passkey

Once 2FA is on, the strongest move is to add a passkey, which replaces the password-plus-code routine with your fingerprint, face, or device PIN and cannot be phished on a fake page. Our guide to setting up passkeys walks through turning them on for Google, Microsoft, and Apple. And because a second factor exists mainly to survive a stolen password, it works best alongside knowing how to spot a phishing email before you ever type a code into the wrong box. Turn on 2FA everywhere that offers it, keep your recovery codes somewhere safe, and move your most important accounts to a passkey when you can.

Discussion

    Leave a comment