Tools · Passwords and sign-in
Turning on two-step sign-in
Two-step sign-in (also called two-factor or multifactor authentication) means a stolen password alone can't open your account. Turn it on for your most sensitive accounts first: bank, credit cards, email, social media, tax site and payment apps. Choose a passkey, security key or authenticator app over text codes when offered, because text codes can be stolen with a SIM swap. Save the backup codes somewhere safe, and never give a code to anyone who contacts you.
You'll need
- Your phone
- Your account logins (ideally in a password manager)
- A safe place for backup codes
What to know
- Pick the strongest method offered. Security keys are strongest, because there's no code to steal. Authenticator apps like Google Authenticator, Microsoft Authenticator or Duo are safer than text or email codes. Source: FTC1 If a site offers a passkey, take it. Source: Cybersecurity Alliance3
Two-step methods, strongest first
From the FTC and the National Cybersecurity Alliance. Source: FTCCybersecurity Alliance13
| Method | How it works | Weak spot |
|---|---|---|
| Passkey | A key stored on your device plus your face or fingerprint | Can't be guessed, reused or phished in the usual way |
| Security key | A small physical device you plug in or tap | Strongest; no credential for hackers to steal |
| Authenticator app | Makes a new code about every 30 seconds, or sends a push to approve | Safe from SIM swaps and email hacks |
| Text or email code | A one-time code, usually 6 digits | SIM swaps can steal texts; a hacked email exposes codes |
See it done
Video by CISA Government
Make Your Accounts Safer with Multifactor Authentication (MFA)
2023 · Checked October 3, 2026
Video won't load at school or work? No problem. Everything you need is in the steps; the video's just a bonus. Watch it on YouTube later.
If it doesn't work
- Only text codes offered? Use them; it's better than nothing. Source: FTC1
- Lost your phone? Sign in with a backup code, then set up two-step again on your new phone. Source: Google4
- Account already hacked? Follow the FTC's steps to recover a hacked email or social media account. Source: FTC5
- Account doesn't offer two-step at all? CISA suggests asking the company why not. Source: CISA2
Good to know
The details, if you want them. Tap a line to open it.
Take it with you
Printable cardDownload card (PDF)Sources
- Federal Trade Commission Use two-factor authentication to protect your accounts
- Cybersecurity and Infrastructure Security Agency Turn on MFA (archived)
- National Cybersecurity Alliance Multi-factor authentication
- Google Company source: its own product instructions Sign in with backup codes
- Federal Trade Commission How to recover your hacked email or social media account
Lesson T3.2 · Last checked October 2, 2026 against the sources listed.
Find it online:
Once a week, if you want it
One new lesson or checklist a week. Totally optional. The lessons never need a sign-up.