What a second factor adds
Two-factor authentication (2FA) combines two different kinds of evidence: something you know, such as a password, and something you have, such as a security key or phone. Biometrics, such as a fingerprint, can form part of verification in supported systems.
A second factor reduces the risk that a stolen password is enough to sign in. It cannot prevent every attack. A one-time code or an approval given without checking can still be exploited through phishing.
Which method to choose
Where supported, a FIDO security key provides resistance to phishing that an ordinary one-time code does not. An authenticator app generates a code on the device; SMS delivers one in a text message. Your choice depends on the service and, for work accounts, your organisation’s requirements.
Start with email, financial accounts and work services. Do not postpone enabling available protection while waiting for a method the service does not yet offer.
Enable protection and prepare for recovery
- Open the official app or website and find the security settings.
- Choose 2FA, multi-factor authentication or two-step verification, depending on the provider’s terminology.
- Follow the selected method’s instructions and check that signing in works.
- If the service provides backup codes, keep them somewhere secure. Check recovery and transfer options before replacing your phone.
Choose your service in the account settings guide for menu paths and the check before replacing a phone.
If an unexpected approval arrives
Decline a request you did not initiate. Do not read out or forward one-time codes. Open the account independently and review recent sign-ins; tell your IT team if it is a work account.
If you already approved the request or shared a code, follow account recovery guidance. If the request concerns banking or a payment, contact your bank immediately through an official channel and explain what you approved.