Practical digital skills

Turn on two-factor authentication safely

Add a second sign-in factor to an important account and prepare a recovery route before you need it.

Step-by-step guideUpdated
Follow the method ↓
A person reviews account security settings beside a mobile phone

The answer in 30 seconds

Two-factor authentication adds another check to a password sign-in. The available methods differ by service, so use the account's own security settings and read its recovery options.

Start with an important account, enable a supported second factor in its official settings, complete a test sign-in and store recovery codes separately from the device you use to sign in.

Examples to adapt

Protecting email

Secure the mailbox used to reset other accounts, then check its recovery address and devices.

Changing phones

Confirm how the authenticator or passkey transfers before wiping the old device.

Unexpected approval prompt

Reject it and inspect account activity through the official app; do not approve a sign-in you did not initiate.

Follow the method

  1. 1
    Open account security settings

    Use the service's known app or website, not a link in an unexpected message.

  2. 2
    Compare available methods

    Choose the strongest practical option supported by both the service and your devices.

  3. 3
    Register the second factor

    Follow the service's setup instructions and confirm a test sign-in before closing the settings.

  4. 4
    Save recovery options

    Store recovery codes or a backup method somewhere secure and separate from the primary device.

  5. 5
    Review later

    Remove old devices and check recovery details when a phone, email address or work role changes.

A checklist to keep

Use these checks to record what you found. The grid supports a decision; it does not make one for you.

Turn on two-factor authentication safely: checklist
CheckWhat to examineAction
AccountWhich important account is being protected?Choose
MethodWhat second factor does the service support?Compare
TestDoes a fresh sign-in work as expected?Confirm
RecoveryWhere are backup codes or methods kept?Store
DevicesAre old authenticators still registered?Review

Download the CSV checklist

Free, no sign-up. UTF-8 text with semicolon-separated columns.

What to check

Two passwords do not make two independent factors.

A one-time code can still be stolen by a convincing phishing page.

Losing the only second factor can lock you out if recovery was not prepared.

Common questions

Is a text-message code better than nothing?

It adds a check, but methods vary in resistance to phishing and account takeover. Use a stronger supported option when practical.

Should recovery codes be kept on the same phone?

A separate secure location is safer if that phone is lost, broken or inaccessible.

Sources and documentation

Documentation consulted on . Examples are illustrative; interfaces and results may change.

Continue exploring

All English guides →