Anúncios
A leaked password is not rare anymore. Big data breaches put billions of email and password pairs into circulation, and scam texts and fake login pages collect the rest. Two-factor authentication (2FA) is what stands between a stolen password and someone actually getting into your account, because the attacker also needs something only you have: your phone, a code app, a passkey, or a physical key.
This guide explains the different kinds of 2FA in plain terms, which ones are worth using, and how to set them up step by step on the accounts that matter most. You will also see how to save backup codes so a lost phone does not lock you out, which is the part most people skip and later regret.
Plan on about 15 minutes for your first two or three accounts. After that, each one takes two or three minutes.
What two-factor authentication actually is
When you sign in, the site normally checks one thing: something you know (your password). 2FA adds a second, different kind of proof, usually something you have (your phone or a key) or something you are (your face or fingerprint, used to open a passkey).
You will also see it called two-step verification (Google’s name), multi-factor authentication or MFA (common at work), or login approvals. They all mean the same idea. Once it is on, you usually only do the second step on a new phone, a new browser, or after you sign out, not every single time.
The four types of 2FA, from weakest to strongest
Not all 2FA is equal. Any of these is much better than a password alone, but they protect you differently.
| Method | How it works | Main weakness | Good for |
|---|---|---|---|
| Text message (SMS) code | A 6-digit code is texted to you | SIM swapping and fake login pages that ask for the code | Accounts with no other option |
| Authenticator app | An app makes a new 6-digit code every 30 seconds | A fake login page can still ask you to type the code | Most accounts |
| Passkey | Your phone signs you in with Face ID, fingerprint or PIN | Needs a phone or password manager that stores it | Google, Apple, Microsoft, Amazon, many banks |
| Security key | A small USB or NFC key you tap | Costs money, you need a backup key | Email, password manager, high-risk accounts |
Text message codes
SMS codes are the easiest to set up and the weakest. In a SIM swap, a scammer talks your carrier into moving your number to their SIM card, and your codes go to them. They also fall to fake login pages: you type your password and the code into the fake page, and the scammer uses both in real time. Google’s own 2-Step Verification help page warns that text and voice codes are more exposed to phone-number attacks. Still, SMS beats nothing. Use it where it is the only option, and ask your carrier to add a port-out PIN or a number lock to your line.
Authenticator apps
An authenticator app generates time-based codes on your phone, so nothing is sent over the phone network. SIM swaps do not affect it. This is the right default for most accounts. The only catch: if you type the code into a convincing fake site, it can still be stolen. Our guide on how to spot text message scams covers how those fake pages reach you.
Passkeys
A passkey replaces the password entirely. Your phone or password manager stores it, and you sign in by confirming with your face, fingerprint or screen lock. Passkeys only work on the real website they were made for, so a fake page cannot trick you into handing one over. Google notes that signing in with a passkey skips the separate second step, because the passkey already proves you have the device. If a service offers passkeys, use them.
Hardware security keys
A security key (YubiKey and Google Titan are the well-known brands, around $25 to $60 each) is a small device you plug in or tap against your phone. Like passkeys, it only works on the real site. It is the strongest option and is worth it for your main email and your password manager if you are a likely target or just want the best protection. Always register two keys and keep one somewhere safe at home.
Which accounts to secure first
Do not try to do everything today. Start with the accounts that can reset everything else.
- Your main email account (Gmail, Outlook, iCloud Mail, Yahoo). Whoever controls your email can reset almost every other password.
- Your Apple Account or Google Account, which control your phone backups, photos and the ability to locate or erase your phone.
- Your password manager, if you use one.
- Banks, credit cards, investment accounts and payment apps like PayPal and Venmo.
- Your mobile carrier account, to protect against SIM swaps.
- Social media accounts, especially ones linked to a business or many followers.
- Shopping accounts with saved cards, such as Amazon.
Step by step: Google Account (Android and iPhone)
On any device, go to your Google Account at myaccount.google.com. On an Android phone, the quick path is Settings > Google > Manage your Google Account > Security & sign-in (Samsung phones list Google further down in Settings, but the path is the same).
- Under “How you sign in to Google,” tap 2-Step Verification and follow the steps to turn it on. Google will usually start with Google prompts, which are yes or no notifications on your signed-in phone.
- Add a passkey: in the same section, tap Passkeys and security keys, then Create a passkey. On Android it is stored in Google Password Manager; on iPhone, in Apple Passwords or your password manager.
- Add an authenticator app: tap Authenticator, then Set up authenticator, and scan the QR code with your app.
- Get backup codes: tap Backup codes and get a set of ten 8-digit codes. Google explains how they work on its backup codes help page.
- Once you have prompts, a passkey and an authenticator app, consider removing the phone number as a 2FA method, keeping it only as a recovery number.
Step by step: Apple Account on iPhone (iOS 26)
Most Apple Accounts created in recent years already have two-factor authentication turned on, and you cannot turn it off after 14 days. To check, go to Settings > [your name] > Sign-In & Security. You should see Two-Factor Authentication: On. Apple’s page on two-factor authentication for Apple Account has the details.
Apple’s version works a bit differently from Google’s. Codes appear automatically on your other trusted Apple devices, and you cannot use a third-party authenticator app for your Apple Account. What you can do in that same Sign-In & Security screen:
- Check Trusted Phone Numbers and add a second number (a partner’s or family member’s) in case you lose yours.
- Add Security Keys if you own two hardware keys. Apple requires at least two, and explains why on its Security Keys for Apple Account page.
- Set up Account Recovery with a recovery contact you trust. This is a safer backup than a recovery key for most people.
A recovery key (Settings > [your name] > Sign-In & Security > Recovery Key) is optional and strict: if you lose it along with your devices, Apple cannot help you get back in. Only turn it on if you will store it somewhere safe and offline.
Step by step: everything else with an authenticator app
Most other services (Amazon, Facebook, Instagram, banks, Microsoft, Dropbox) follow the same pattern.
- Open the account’s security settings. Look for “Two-factor authentication,” “2-step verification,” “Login security” or “Sign-in and security.”
- Choose “Authenticator app” (sometimes “Security app” or “Third-party authenticator”). Skip the text message option if this one is offered.
- Open your authenticator app, tap the plus button, and scan the QR code on screen. If you are setting it up on the same phone, choose “Enter a setup key” and copy the long code instead.
- Type the 6-digit code from the app into the website to confirm.
- Save the backup codes the site shows you (more on that below).
Which authenticator app to use
Any of these works with almost every site. The main difference is how they back up your codes, which matters when you change phones. If you already use a paid password manager, it may include one: 1Password does, and Bitwarden includes it in its Premium plan. Our guide to the best password manager apps compares them.
Google Authenticator
Google’s free app is the simplest. Since 2023 it can sync your codes to your Google Account, so a new phone gets them back after you sign in. The limitation: it has very few extras, and if you choose not to sign in, you must use its Transfer accounts option to move codes to a new phone yourself. It is a good pick for Android users and anyone who wants something plain.
Microsoft Authenticator
Free, and the best choice if you use a Microsoft account for work or Outlook, because it can approve Microsoft sign-ins with a tap and supports passkeys for Microsoft accounts. It also makes regular 6-digit codes for other sites. The limitation: Microsoft removed its password autofill feature in 2025, so it is now an authenticator only, and its cloud backup works differently on iPhone (iCloud) and Android (your Microsoft account).
Ente Auth
Ente Auth is free and open source, with end-to-end encrypted backup that syncs across iPhone, Android and the web. It is my pick if you switch between Android and iPhone, because the backup is not tied to Google or Apple. The limitation: you need to create an Ente account and remember its password, since the company cannot read or recover your codes without it.
Backup codes and lost phones
Every service that offers 2FA gives you a way back in if you lose your phone, usually a list of one-time backup codes. Save them the moment you turn on 2FA. Good places are your password manager (in a secure note for that account) or a printed sheet in a drawer at home. Bad places are a screenshot in your camera roll or a note in an app that itself needs 2FA to open.
When you get a new phone, move your authenticator codes before you wipe or trade in the old one. With sync turned on (Google Authenticator signed in, Microsoft Authenticator backup on, or Ente Auth) the codes come back when you sign in on the new phone. Check that a few accounts work on the new phone first. If you are changing platforms, our guide on switching from Android to iPhone covers the rest of the move.
If your phone is lost or stolen with 2FA on it, your backup codes and trusted devices are what get you back in. Our checklist on what to do if your phone is lost or stolen walks through it.
Common questions
Is two-factor authentication worth the hassle?
Yes. Microsoft and Google have both reported that accounts with 2FA turned on are far less likely to be taken over. Most services only ask for the second step on new devices, so day to day you will barely notice it.
What if a site only offers text message codes?
Use it anyway. It still blocks attackers who only have your password. Then protect your phone number with a carrier PIN, and keep an eye out for the site adding app or passkey support later.
Someone sent me a 2FA code I did not ask for. What now?
That means someone has your password and is trying to sign in. Do not share the code with anyone, even someone claiming to be support. Change that account’s password right away from the real website or app.
A 15-minute setup for this weekend
Pick one authenticator app and add it to your phone. Then secure three accounts in this order: your main email, your Apple Account or Google Account, and your bank. On each, turn on passkeys if offered, add the authenticator app, and save the backup codes in your password manager or on paper. Next weekend, do the rest of the list. That small amount of work closes the door that most account takeovers walk through.




