How to Set Up Two-Factor Authentication (2FA)
Two-factor authentication — 2FA, also called MFA or two-step verification — is the single most effective thing you can do to protect your online accounts. Here's why it matters so much: even if a criminal steals or guesses your password, they still can't get in without the second factor sitting on your phone. It takes a few minutes per account, it's free, and it stops the overwhelming majority of account takeovers cold. This guide walks you through setting it up, in plain English.
Why a password alone isn't enough
Passwords leak constantly — through data breaches, phishing emails and simple reuse across sites. Once a password is out, automated tools try it everywhere. Two-factor authentication breaks that chain: the password becomes only half of what's needed, and the other half is something only you have. It's the difference between a single lock and a lock plus a deadbolt that needs a key only you carry. If you do nothing else for your digital security this year, do this.
1. Start with your email
Your email account is the master key to everything else — if someone controls it, they can request password resets for your bank, your shopping accounts and your social media, and quietly take them all. So secure your email first, then work outwards to your other important accounts. Protecting email is genuinely the highest-value five minutes in all of personal security.
2. Open your security settings
In your account's settings, find the section called "Security", then look for "2-Step Verification", "Two-Factor Authentication" or "Two-Step Verification" — the wording varies by provider but the idea is identical.
3. Add an authenticator app (the best option)
Where you have the choice, use an authenticator app rather than text-message codes. Texts can be intercepted or redirected (a trick called SIM-swapping), whereas an app generates codes on your device that never travel over the network. Install a reputable authenticator app, then scan the on-screen QR code with it and enter the six-digit code it shows to confirm. From then on, the app produces a fresh code whenever you log in. Text-message 2FA is still far better than none — so if that's all an account offers, use it.
4. Save your backup codes
When you turn on 2FA you'll be given a set of recovery or backup codes. These are your way back in if you ever lose your phone — so don't skip them. Store them somewhere safe and separate: printed and tucked away, or saved in a password manager. People who get locked out of their own accounts almost always skipped this step.
5. Repeat for your other key accounts
With email done, turn 2FA on for the rest of what matters: online banking, your Apple or Google account, social media, and anything tied to money or your identity. Most major services support it now, and many will nudge you to enable it. Twenty minutes spread across your important accounts buys an enormous amount of protection.
What to do if you lose your phone
This is the worry that stops people enabling 2FA — but it's manageable. Your backup codes will get you in, and most authenticator apps can now sync or restore to a new phone via your account. The key is to set up that recovery before disaster strikes: save your codes, and if you're moving to a new phone, transfer or re-register your authenticator before wiping the old one. See our guide to setting up a new iPhone or a new Android phone for the order to do things in.
Watch out for "MFA fatigue" attacks
One modern scam is worth knowing about: attackers who already have your password will trigger repeated approval prompts, hoping you'll tap "approve" out of annoyance or by accident. The rule is simple — never approve a login prompt you didn't start yourself. If prompts arrive out of nowhere, that's a sign your password has leaked, so change it straight away. Combine 2FA with the habits in our passwords and MFA guide and you've closed the door on the vast majority of attacks.
Securing a whole team?
Rolling out enforced 2FA, a shared password manager and clear, simple policies across a business is one of the highest-value, lowest-cost security wins there is — and it heads off the email and invoice fraud that catches so many firms. Our cyber security and business IT support teams set it all up and support your staff so good security becomes the easy default.
Official guidance: The UK’s NCSC Cyber Aware campaign recommends turning on two-factor authentication for your email and key accounts as one of the most effective steps you can take.