How do I set up two-factor authentication?
Setting up 2FA on the accounts that matter, choosing between app, SMS and hardware key, and not locking yourself out.
- Difficulty
- beginner
- Time
- 45 min
- Read
- 2 min
Short answer
Start with your email account, then banking and anything holding payment details. Use an authenticator app rather than SMS where possible, and save the recovery codes somewhere safe before you finish — losing your second factor without them can lock you out permanently.
Two-factor authentication protects an account even when the password is compromised, which is why it matters more than password complexity. The main risk in setting it up is locking yourself out, and that is entirely avoided by saving the recovery codes.
What you'll need
- Authenticator app
- Somewhere secure for recovery codes
- Hardware security key (optional)
Step by step
- Start with your primary email account.Whoever controls your email can reset the password on almost every other account you own. It is the highest-value target.
- Install an authenticator app on your phone.It generates time-based codes offline, so it works without signal and cannot be intercepted by SIM swapping.
- In the account's security settings, choose to add an authenticator app.It displays a QR code. Scan it with the app and the account appears in your list.
- Enter the code the app displays to confirm the pairing.Codes rotate every 30 seconds. If it fails, check your phone's clock is set automatically.
- Save the recovery codes before finishing.This is the critical step. Print them, or store them in your password manager. Without them, losing your phone can mean permanent lockout.
- Repeat for banking, payment services and anything holding card details.Work down in order of what a compromise would cost you.
- Use SMS only where nothing better is offered.It is much better than nothing and stops most automated attacks, but it can be intercepted through SIM swapping.
- Consider a hardware security key for your most important accounts.A physical key is the strongest option and cannot be phished, because it verifies the site as well as you.
Tips
- Add each account to your authenticator app on two devices, or make sure the app's own backup is enabled, so a lost phone is not a crisis.
- Passkeys are increasingly replacing both passwords and 2FA on major services, and are more secure than either.
- Before changing phones, transfer your authenticator accounts using the app's own migration feature — many do not transfer in a normal phone backup.
Common mistakes
- Not saving recovery codes — A lost or broken phone can then mean permanent loss of access to the account.
- Setting up 2FA on everything except email — Email resets everything else. It has to be first.
- Assuming authenticator apps transfer with a phone backup — Many do not. Use the app's own migration process before retiring the old phone.
Questions people ask
Is SMS two-factor authentication worth using?
Yes where nothing better is available — it stops most automated attacks. It is weaker than an authenticator app because SIM swapping can intercept it, so prefer an app when offered the choice.
What happens if I lose my phone?
You use the recovery codes you saved when setting it up. Without those, regaining access depends entirely on the service's account recovery process, which can be slow or impossible.