Everything, A to Z Help now

Tools · Passwords and sign-in

Turning on two-step sign-in

Two-step sign-in (also called two-factor or multifactor authentication) means a stolen password alone can't open your account. Turn it on for your most sensitive accounts first: bank, credit cards, email, social media, tax site and payment apps. Choose a passkey, security key or authenticator app over text codes when offered, because text codes can be stolen with a SIM swap. Save the backup codes somewhere safe, and never give a code to anyone who contacts you.

Easy5 min per accountFreeChecked October 2, 2026

You'll need

  • Your phone
  • Your account logins (ideally in a password manager)
  • A safe place for backup codes

What to know

  1. Open the account's settings, then its security section. It may be called Security, or Password and Security. Source: CISA2
  2. Look for two-factor authentication, two-step verification or multifactor authentication. It usually isn't on by default. Source: FTC1
  3. Pick the strongest method offered. Security keys are strongest, because there's no code to steal. Authenticator apps like Google Authenticator, Microsoft Authenticator or Duo are safer than text or email codes. Source: FTC1 If a site offers a passkey, take it. Source: Cybersecurity Alliance3
  4. Save your backup codes. They let you sign in if you lose your phone or change your number. Each works once, and you can print them and keep them with your passport or other important papers. Source: Google4
  5. Start with your most sensitive accounts: bank, credit cards, email, social media, tax filing site and payment apps. Then add shopping sites. Source: FTC1 Don't skip email: in CISA's example, a hacked email let scammers into a bank account and other linked accounts. Source: CISA2
  6. Let it remember only your own devices, never a library or other public computer. Source: FTC1
Watch out Never share a verification code with someone if you didn't contact them first, no matter the story. Source: FTC1 Getting a flood of login approval requests you didn't start? That's "push bombing," meant to get you to tap approve by accident. Deny them and change your password. Source: Cybersecurity Alliance3

Two-step methods, strongest first

From the FTC and the National Cybersecurity Alliance. Source: FTCCybersecurity Alliance13

MethodHow it worksWeak spot
PasskeyA key stored on your device plus your face or fingerprintCan't be guessed, reused or phished in the usual way
Security keyA small physical device you plug in or tapStrongest; no credential for hackers to steal
Authenticator appMakes a new code about every 30 seconds, or sends a push to approveSafe from SIM swaps and email hacks
Text or email codeA one-time code, usually 6 digitsSIM swaps can steal texts; a hacked email exposes codes

See it done

Video by CISA Government

Make Your Accounts Safer with Multifactor Authentication (MFA)

2023 · Checked October 3, 2026

Video won't load at school or work? No problem. Everything you need is in the steps; the video's just a bonus. Watch it on YouTube later.

If it doesn't work

  • Only text codes offered? Use them; it's better than nothing. Source: FTC1
  • Lost your phone? Sign in with a backup code, then set up two-step again on your new phone. Source: Google4
  • Account already hacked? Follow the FTC's steps to recover a hacked email or social media account. Source: FTC5
  • Account doesn't offer two-step at all? CISA suggests asking the company why not. Source: CISA2

Good to know

The details, if you want them. Tap a line to open it.

Why a password isn't enough

Hackers phish for passwords, buy ones stolen in data breaches, and try them on your other accounts if you reuse them. Source: FTC1

Three kinds of factors

Something you know (a password or PIN), something you have (a code or security key), and something you are (a fingerprint or face). Two-step uses two of the three. Source: FTC1

Take it with you

Printable cardDownload card (PDF)

Sources

  1. Federal Trade Commission Use two-factor authentication to protect your accounts
  2. Cybersecurity and Infrastructure Security Agency Turn on MFA (archived)
  3. National Cybersecurity Alliance Multi-factor authentication
  4. Google Company source: its own product instructions Sign in with backup codes
  5. Federal Trade Commission How to recover your hacked email or social media account

Lesson T3.2 · Last checked October 2, 2026 against the sources listed.

Report a mistake

Next in ToolsSpotting a scam text or call

Need help now?

If you or someone else is in danger, call 911 first. These lines are free, and someone answers.

What to do first, step by step