Prevention
Set Up 2FA in 5 Minutes
Guide on how to set up two-factor authentication (2FA)
Two-factor authentication. 2FA. Multi-factor authentication. MFA. You've heard these terms and probably been nagged to turn it on. Here's the thing — it's the single most effective thing you can do to protect your online accounts, and it takes less time than making a cup of coffee.
## What this guide covers
- What 2FA actually is (one paragraph, we promise) - The different types and which one to pick - How to turn it on for your most important accounts - What to do so you don't lock yourself out
---
## What Is 2FA?
When you log into an account with just a password, that's one factor — something you know. Two-factor authentication adds a second factor — usually something you have, like your phone. So even if someone steals your password, they still can't get into your account because they don't have the second piece.
That's it. That's the whole idea.
---
## Why It Matters
Passwords get stolen all the time — through data breaches, phishing, or just being guessed. If your password is the only thing between a hacker and your account, you're relying on a single lock on the front door.
2FA adds a deadbolt. Even if someone picks the first lock, they're stopped at the second one.
---
## The Types of 2FA (And Which to Use)
Not all 2FA is created equal. Here are the common options, ranked from good to best.
### SMS codes (good)
You get a text message with a code every time you log in. This is the most common type and it's better than nothing — significantly better. However, it has a known weakness: SIM swapping, where an attacker convinces your phone carrier to transfer your number to their device. This is rare for most people but worth knowing about.
**Use SMS 2FA if it's the only option available.** It's still a massive upgrade over no 2FA at all.
### Authenticator apps (better)
An app on your phone generates a new code every 30 seconds. The code exists only on your device — it's not sent over a text message, so it can't be intercepted.
Popular authenticator apps include Google Authenticator, Microsoft Authenticator, and Authy. They're all free and work with most services.
**This is what we recommend for most people.** It's easy to set up, free, and significantly more secure than SMS.
### Hardware security keys (best)
A physical device (like a USB key) that you plug in or tap when logging in. It's nearly impossible to phish because the key verifies the actual website, not just a code.
**This is overkill for most people.** But if you're in a high-risk situation — journalist, activist, public figure, business owner — it's worth considering.
### Biometrics (supplementary)
Fingerprint or face recognition. These are great as a convenience layer on your device but are usually used alongside one of the methods above, not as a replacement.
---
## How to Set It Up (The 5-Minute Part)
The process is similar across most platforms. Here's the general approach:
### Step 1: Go to your account's security settings
Log into the account you want to protect. Navigate to Settings, then look for "Security," "Privacy," or "Sign-in." Look for "Two-factor authentication," "2-step verification," or "Multi-factor authentication."
### Step 2: Choose your method
Select authenticator app if available (recommended). Otherwise, select SMS.
### Step 3: If using an authenticator app
The platform will show you a QR code. Open your authenticator app, tap the option to add a new account, and scan the QR code. The app will start generating codes. Enter the current code on the platform to confirm it's working.
### Step 4: If using SMS
Enter your phone number. The platform will send you a code to verify it works. Enter the code.
### Step 5: Save your backup codes
Almost every platform will give you a set of backup codes after setting up 2FA. These are one-time-use codes that let you get back into your account if you lose access to your phone.
**This is important. Save these somewhere safe.** Print them out, write them down, or store them in a secure location that isn't on the device you're using for 2FA. If you lose your phone and don't have backup codes, getting back into your accounts can be a painful process.
---
## Which Accounts to Secure First
You don't need to do everything at once. Start with the accounts that matter most:
**Your email** — this is the master key. If someone controls your email, they can reset passwords on almost everything else. Secure this first.
**Your banking and financial apps** — anywhere your money lives.
**Cloud storage** — Google Drive, iCloud, Dropbox, etc. These often contain personal documents, photos, and sensitive information.
**Social media** — especially if you use these accounts for business or have a significant following.
**Password manager** — if you use one (and you should), 2FA on your password manager is critical since it holds the keys to everything.
---
## Common Concerns
### "What if I lose my phone?"
This is why backup codes exist. Save them when you set up 2FA. You can also usually set up multiple 2FA methods — for example, an authenticator app as your primary and SMS as a backup.
If you use an authenticator app like Authy, it can sync across devices and back up to the cloud, which makes recovery easier.
### "Won't this make logging in annoying?"
Slightly. You'll spend an extra 10 seconds entering a code. Most platforms remember your device, so you won't need to do it every single time — just when logging in from somewhere new. That 10-second inconvenience is the price of not having your account taken over.
### "I'm not a target — do I really need this?"
You don't need to be a target. Automated attacks try stolen passwords across millions of accounts. 2FA stops them cold, regardless of who you are.
### "What if the website doesn't offer 2FA?"
Not every site does, but most major ones do. If a service you use doesn't offer any form of 2FA, at minimum make sure you're using a strong, unique password for that account. And consider whether a service that doesn't invest in basic security deserves your trust with your data.
---
## You're Done
That's it. If you've turned on 2FA for your email and saved your backup codes, you've already made yourself dramatically harder to hack. Do the rest of your important accounts when you have a few more minutes, and you're in good shape.
It's one of those rare things in life where five minutes of effort gives you a massive return.
> **Want to learn more about protecting yourself online?** Check out our other guides on the [StillOnline.org home page].
---
*This guide is part of the StillOnline.org prevention series. Written in plain language for real people who want to stay safe without a computer science degree.*
Need help reporting or recovering?
Find where to report cyber crime in your country and where to get support.
Get help