A password can be stolen, guessed or reused. Two-factor authentication (often called 2FA or two-step verification) asks for another proof of identity when someone tries to sign in.
1. Open the account’s official security settings
Sign in through the service’s official website or app. Look for Security, Login security, Two-factor authentication or Two-step verification. Do not follow a 2FA setup link from an unexpected email or text.
2. Choose the strongest method you can use reliably
An authenticator app or a security key is usually stronger than codes sent by SMS. SMS can still be better than using only a password, but it can be vulnerable if a criminal takes over your phone number. Choose a method you will be able to access when travelling or changing phones.
3. Save backup codes safely
Many services show one-time backup codes. Store them in a password manager or another secure place you can reach if your phone is lost. Do not keep them in an unprotected photo, public cloud note or email draft.
4. Add recovery options you control
Check that the recovery email address and phone number are current. Remove old numbers and devices. If an account lets you add a second authenticator or security key, consider keeping it as an emergency backup.
5. Test before signing out
Open a private browser window or another device and sign in once using the new method. This confirms that codes, prompts or keys work. Only then sign out of your main session.
6. Treat unexpected codes as an alert
If you receive a code or approval prompt you did not request, do not approve it. Change the account password from the official site, review signed-in devices and contact the service’s official support if needed.