How to Set Up Two-Factor Authentication (2FA) on Your Accounts

By Ammar Aslam · Updated September 16, 2026 · 8 min read
How to Set Up Two-Factor Authentication (2FA) on Your Accounts

Passwords get stolen all the time, through data breaches, fake login pages and malware. Two-factor authentication, usually shortened to 2FA, is a simple extra step that stops most of these attacks. Even if someone has your password, they cannot get into your account without the second factor.

This guide explains how 2FA works, compares the different methods, and shows you how to switch it on for the accounts you use most.

How two-factor authentication works

Normally you prove who you are with one thing: something you know, your password. 2FA adds a second, different kind of proof, usually something you have, such as your phone, or something you are, such as your fingerprint.

When you log in from a new device, you enter your password and then confirm with that second factor. On devices you trust, most services remember you, so you do not have to do it every time.

Types of 2FA, from weakest to strongest

MethodHow it worksSecurity
SMS codeA code is texted to your phoneGood (better than nothing)
Authenticator appAn app generates a new code every 30 secondsVery good
Push promptYou tap "Yes, it's me" on your phoneVery good
Passkey or security keyYour device or a USB/NFC key confirms it's youExcellent

SMS is the most common but also the weakest, because attackers can sometimes hijack phone numbers through a "SIM swap" scam. Whenever an authenticator app or passkey is available, prefer it.

Setting up an authenticator app

Popular free authenticator apps include Google Authenticator, Microsoft Authenticator and Authy. Many password managers can also generate these codes. The setup process is nearly identical everywhere:

  1. Install an authenticator app on your phone.
  2. In your account's security settings, choose Authenticator app as your 2FA method.
  3. The website shows a QR code. In the authenticator app, tap + and scan it.
  4. Type the six-digit code shown in the app into the website to confirm.
  5. Save the backup codes the website gives you.
Do not skip the backup codes. If you lose or reset your phone, backup codes are often the only way back into your account. Store them somewhere safe and offline, such as a printed copy at home or in your password manager.

Turn on 2FA for your Google account

  1. Go to your Google Account and open the Security section.
  2. Under How you sign in to Google, select 2-Step Verification.
  3. Follow the prompts. Google will suggest phone prompts by default. You can also add an authenticator app and passkeys.

Because your Gmail account can reset passwords for most other services, this is the most important account to protect.

Turn on two-step verification in WhatsApp

  1. Open WhatsApp and go to Settings → Account → Two-step verification.
  2. Tap Turn on and create a six-digit PIN.
  3. Add an email address so you can reset the PIN if you forget it.

This stops scammers from registering your number on another phone, even if they trick you into sharing the SMS code. Remember: never share a WhatsApp verification code with anyone, even if the message seems to come from a friend.

Facebook and Instagram

Meta manages security for both apps from the Accounts Center. Open settings in either app, go to Accounts Center → Password and security → Two-factor authentication, pick your account, and choose an authenticator app or SMS.

Banking and payment apps

Most banks and mobile wallet apps already use one-time codes and device binding. Check the app's security settings for options such as biometric login and transaction alerts, and turn them on. Never share a one-time code over the phone; real banks will not ask for it.

Which accounts to secure first

  1. Your main email account
  2. Your password manager
  3. Banking and payment apps
  4. WhatsApp and other messaging apps
  5. Social media accounts
  6. Cloud storage such as Google Drive, iCloud or OneDrive

Frequently asked questions

What if I lose my phone?

Use one of your saved backup codes to sign in, then remove the old phone and set up 2FA again on your new device. This is why saving backup codes is so important.

Does 2FA make logging in annoying?

Only slightly. Most services ask for the second factor only when you sign in on a new device or browser. On your everyday phone and computer, you rarely see it.

Is SMS 2FA still worth using?

Yes. SMS-based 2FA is much safer than a password alone. If a service only offers SMS, turn it on anyway.

A
Ammar Aslam
Ammar writes clear, practical tech guides that help everyday users fix problems, stay safe online and get more from their devices.