Account protection

Turn on two-step verification without getting locked out

Choose a practical second sign-in method, save recovery options, and test your setup before you finish.

Two-step verification adds another check after your password. You may also see it called two-factor authentication, 2FA, or multi-factor authentication. The names vary, but the purpose is the same: a password alone should not be enough to enter your account.

Your goal for today: turn it on for your main email, then confirm that you have a safe way back in if your phone is lost.

Start with the account that matters most

Begin with your main email account. It often receives password-reset messages for your other services. Next, protect your Apple, Google, or Microsoft account, then banking, payment, mobile carrier, and important social accounts.

If this list feels long, do one account today. The guide to protecting your most important accounts can help you decide what comes next.

Choose the best method you can use reliably

Services may offer several options. They are not all equally resistant to phishing.

Passkeys or security keys

Passkeys and FIDO security keys can check that you are signing in to the real service. NIST describes cryptographic methods like these as phishing-resistant because they do not ask you to type a reusable secret or one-time code into a page.

Use this option when the service supports it and you are comfortable keeping a second recovery method.

An authenticator app

An authenticator app creates a short-lived code on your phone. It is a solid, widely available choice. A convincing fake sign-in page can still ask you to type that code, so open important services from a bookmark or their official app.

A text message or phone call

Text messages are not the strongest option, but they still add a useful barrier when a service offers nothing better. Make sure your mobile carrier account has its own strong password and account PIN.

Set up recovery before you leave the page

The most common mistake is turning on a second step without planning for a lost or replaced phone.

Before you finish:

  1. Confirm your recovery email and phone number.
  2. Generate backup or recovery codes if the service offers them.
  3. Store those codes away from your everyday phone. A printed copy in a private place is fine.
  4. Add a second security key or another approved device if the service allows it.
  5. Tell a trusted household member where the recovery instructions are kept, if that is appropriate for your situation.

Do not keep the only copy of a recovery code in the photo library or cloud account that the code unlocks.

Test the setup calmly

Open a private browsing window or use another device. Sign in using your password and new second step. Then check that you can find your recovery settings without changing them.

Do not sign out of every trusted device at once. Keep one working session open until the test succeeds.

If you receive a code you did not request

Do not approve the prompt and do not share the code. Open the service through its official app or a saved bookmark. Review recent sign-ins, change a reused or exposed password, and contact the service through its official support route if you see activity you do not recognize.

Your sensible stopping point

You are done for today when your main email has a second sign-in step, current recovery details, and backup codes stored somewhere separate.

Next, use the household safety check or prepare for a device change with the new phone setup guide.

Official sources