Two-factor authentication (2FA) means logging in requires your password plus a second proof — usually a code or a physical key. It's the single most effective step against account takeover, but the way most people set it up leaves a gap: no backup plan for when they lose their phone.

The three main types, ranked by strength

Step 1: Prioritize which accounts get 2FA first

Start with your email account — it's usually the recovery method for everything else, so it's the highest-value target. Then move to financial accounts, then any account tied to your identity (social media, cloud storage).

Step 2: Set up an authenticator app

In the account's security settings, look for "Two-factor authentication" or "2-Step Verification." Choose "Authenticator app," which will show a QR code. Open your authenticator app, add a new account, and scan the code. The app now generates a new 6-digit code every 30 seconds that you'll enter alongside your password at login.

Step 3: Save your backup codes — don't skip this

Every major service generates one-time backup codes when you enable 2FA. This is the step almost everyone skips, and it's the one that matters most: if your phone is lost, stolen, or replaced, backup codes are how you get back into your account without waiting on a support ticket. Save them somewhere other than your phone — a password manager's notes field, or printed and stored somewhere secure.

Step 4: Plan for a lost or replaced phone

Before you need it, know your recovery path: most authenticator apps let you export or back up your codes to a new phone (Authy does this by default; Google Authenticator added transfer support in recent versions). Set this up when you first install the app, not after you've already lost the old one.

A common mistake: only protecting the account, not the recovery method

If your 2FA recovery email is an old account you don't check, or your recovery phone number is out of date, 2FA can lock you out of your own account. Review and update recovery information at the same time you set up 2FA.

If you manage several accounts, a password manager with built-in 2FA code storage (like 1Password or Bitwarden) can simplify this significantly — one place for passwords and codes, synced across your devices.

Quick setup checklist