2FA Guide: What Is Two-Factor Authentication and How Do You Turn It On?
Learn the differences between SMS, authenticator apps and security keys, how to set up 2FA on popular services, and how to store your backup codes safely.
Table of contents
- What is two-factor authentication and how does it work?
- Why you should use two-factor authentication
- Verification methods: SMS, authenticator apps and security keys
- SMS verification
- Authenticator apps
- Security keys and passkeys
- How to turn on 2FA for popular services
- Which accounts should you secure first?
- Backup codes and recovery options
- Are virtual numbers suitable for 2FA?
- Tips for staying safe
- Conclusion
A strong password alone isn't enough anymore. Data breaches, fake login pages and reusing the same password across many sites are among the most common reasons accounts get hijacked. One of the most effective ways to reduce these risks is two-factor authentication. In this guide, we explain how the method known as 2FA works, the different types of verification, how to turn it on for popular services and how to store your backup codes.
What is two-factor authentication and how does it work?
2FA means you're asked for a second proof of identity in addition to your password when you sign in. In the security world, these proofs fall into three groups:
- Something you know: A password or PIN.
- Something you have: Your phone, an authenticator app or a physical security key.
- Something you are: Biometrics such as a fingerprint or face recognition.
Even if your password is somehow stolen, an attacker still has to get past the second step. That makes taking over your account significantly harder.
Why you should use two-factor authentication
If your password is exposed in a breach on one site, every email, social media and shopping account where you reused it is at risk too. A second step breaks that chain reaction. Many services also alert you to sign-ins from new devices when 2FA is on, so you can spot suspicious attempts early. Be sure to turn it on for your main email account in particular, because password reset links for your other accounts usually go to that address.
Verification methods: SMS, authenticator apps and security keys
SMS verification
A one-time code is texted to your phone when you sign in. It's the easiest method to set up, but it's weaker against attacks like SIM swapping, where scammers move your number to another SIM card. Still, it's far safer than using no 2FA at all. Learn more about how an OTP code works.
Authenticator apps
Apps like Google Authenticator or Microsoft Authenticator generate codes that usually refresh every 30 seconds. Because the codes are created on your device, they don't depend on the mobile network and aren't affected by SIM-based attacks. Don't forget to move your saved accounts to the new device when you switch phones.
Security keys and passkeys
Physical security keys that work over USB or NFC, and passkeys stored on your device, offer the strongest protection against fake login pages. Because the key only works with the real site's address, it's useless on a phishing site.
| Method | Security | Ease of use | Watch out for |
|---|---|---|---|
| SMS code | Basic | Very easy | Vulnerable to SIM swaps |
| Authenticator app | High | Easy | Must be moved when you change phones |
| Security key / passkey | Very high | Moderate | A backup key is recommended |
How to turn on 2FA for popular services
Menu names can vary by app version, but the general path looks like this:
- Google Account: Manage your Google Account → Security → 2-Step Verification.
- Instagram and Facebook: Accounts Center → Password and security → Two-factor authentication.
- WhatsApp: Settings → Account → Two-step verification; set a six-digit PIN and a recovery email.
- Telegram: Settings → Privacy and Security → Two-Step Verification; set an additional password and a recovery email.
- Microsoft account: Turn on additional verification under Security → Advanced security options.
During setup, the service usually shows a QR code. Scan it with your authenticator app, then enter the code the app generates to finish pairing.
Which accounts should you secure first?
Start with your email account, then your password manager, cloud storage and social media accounts. If these are compromised, the door to your other accounts opens too. After that, move on to accounts such as shopping sites with saved payment details and gaming platforms.
Backup codes and recovery options
Backup codes are essential for getting back into your account if you lose your phone or can't access your authenticator app.
- Download or print the backup codes you're given during setup; each code can usually be used only once.
- Store the codes in your password manager or a secure physical place. Don't keep them as screenshots in your photo gallery.
- If possible, add a second method, such as a backup security key or a second device.
- Make sure your recovery email address and phone number are up to date.
Are virtual numbers suitable for 2FA?
Virtual numbers from services like OnaySIM are temporary: the number is reserved for you for a short time, and you may not be able to receive SMS on it later. That's why you should not use a virtual number as a permanent 2FA channel. Virtual numbers are a good fit for one-time verifications, such as keeping your personal number private at sign-up, testing an app or separating your work and personal accounts. For that kind of verification, you can use the get a number page, then set up an authenticator app, backup codes and a recovery email right after creating the account.
You can learn how virtual numbers work in our virtual phone number guide, and find tips for protecting your number in our phone number privacy guide.
Tips for staying safe
- Never share a verification code you receive with anyone by phone or message; real services won't ask you for it.
- A 2FA code you weren't expecting can mean someone else has your password, so change it right away.
- Use a different, strong password for every account; a password manager makes this easy.
- Protect your password manager's main account with extra verification as well, since it holds the keys to all your passwords.
To see how attackers try to get around SMS codes, read our explainer on SIM swap fraud.
Conclusion
Turning on two-factor authentication takes a few minutes but greatly improves your security. Choose an authenticator app or a security key wherever possible, keep your backup codes safe, and use temporary virtual numbers only for one-time sign-ups and testing. The smartest place to start is your main email account, which holds the keys to all your other accounts.


