Two-factor authentication (2FA) means logging in requires your password plus a second proof — usually a code or a physical key. It's the single most effective step against account takeover, but the way most people set it up leaves a gap: no backup plan for when they lose their phone.
The three main types, ranked by strength
- SMS codes — better than nothing, but vulnerable to SIM-swap attacks where someone convinces your carrier to move your number to their device.
- Authenticator apps (Google Authenticator, Authy, Microsoft Authenticator) — generate codes on your device without a network connection, immune to SIM swaps. This is the right default for most people.
- Security keys (physical devices like a YubiKey) — the strongest option, immune to phishing since the key checks the site's identity too. Worth it for email and financial accounts.
Step 1: Prioritize which accounts get 2FA first
Start with your email account — it's usually the recovery method for everything else, so it's the highest-value target. Then move to financial accounts, then any account tied to your identity (social media, cloud storage).
Step 2: Set up an authenticator app
In the account's security settings, look for "Two-factor authentication" or "2-Step Verification." Choose "Authenticator app," which will show a QR code. Open your authenticator app, add a new account, and scan the code. The app now generates a new 6-digit code every 30 seconds that you'll enter alongside your password at login.
Step 3: Save your backup codes — don't skip this
Every major service generates one-time backup codes when you enable 2FA. This is the step almost everyone skips, and it's the one that matters most: if your phone is lost, stolen, or replaced, backup codes are how you get back into your account without waiting on a support ticket. Save them somewhere other than your phone — a password manager's notes field, or printed and stored somewhere secure.
Step 4: Plan for a lost or replaced phone
Before you need it, know your recovery path: most authenticator apps let you export or back up your codes to a new phone (Authy does this by default; Google Authenticator added transfer support in recent versions). Set this up when you first install the app, not after you've already lost the old one.
A common mistake: only protecting the account, not the recovery method
If your 2FA recovery email is an old account you don't check, or your recovery phone number is out of date, 2FA can lock you out of your own account. Review and update recovery information at the same time you set up 2FA.
Quick setup checklist
- Enable 2FA on email first, then financial and identity-linked accounts.
- Prefer an authenticator app or security key over SMS where offered.
- Save backup codes somewhere other than the phone itself.
- Set up authenticator backup/transfer before you need it, not after.
- Keep recovery email and phone number current.