Privacy & security

How to Turn On Two-Factor Authentication Everywhere

By TheTruthSpy Editor · Founder and editorPublished October 6, 202611 min read
Phone on a wooden desk showing a sign-in approval prompt, beside a physical security key, a house key and a laptop

If someone learned your email password tonight, what would stop them? For most accounts without two-factor authentication, nothing. They could sign in, read your messages, and use the “forgot password” links on your bank, shopping and social media accounts to take those over too, all without touching your phone.

Two-factor authentication (2FA), also called two-step verification or 2SV, closes that gap. Signing in needs your password plus a second thing only you have, usually your phone. Both the UK’s National Cyber Security Centre (NCSC) and the US Cybersecurity and Infrastructure Security Agency (CISA) list it among the most effective things you can do to protect your online accounts.

Turning it on everywhere sounds like a weekend job, but the accounts that matter most take one evening. Below: which second step to pick, the order to work through, where each platform keeps the setting, and how not to lock yourself out when you change phones or help a parent.

The short version

  • Start with your main email account, because it can reset the passwords on almost everything else.
  • Any second step is far better than none. Text codes are the weakest option but still block most attacks that rely on a stolen password.
  • Prefer an app prompt, authenticator app or passkey where offered, and keep a text code as a backup.
  • Save each account’s backup codes somewhere safe away from your phone, such as a password manager or a printed sheet at home.
  • Before you wipe or replace a phone, move your authenticator app codes and check you can still sign in.

What the second step actually protects against

Passwords leak in ways you cannot control: a data breach at a website you used years ago, a convincing fake login page, or a password reused across several sites. Criminals collect these and try them automatically on email and shopping accounts. A second step means a correct password on its own is no longer enough.

It does not make you untouchable. A realistic fake page can ask for your code as well as your password and pass both to the real site within seconds. That is why the type of second step matters, and why one rule applies to all of them: never read a code to anyone who contacts you, and never approve a sign-in prompt you did not start.

Laptop sign-in page with a password entered while a phone beside it shows a prompt with a large No button
With a second step on, a stolen password stalls at the prompt on your phone, which you can simply refuse.

The kinds of second step, ranked

Most services let you choose, and many let you add more than one. The order below follows CISA’s guidance: phishing-resistant methods at the top, text and voice codes at the bottom. In the middle, CISA ranks authenticator codes level with prompts that ask you to match a number shown on the sign-in screen, and plain Yes/No prompts a little lower. The NCSC’s summary is the one to remember: any 2-step verification is better than not having it at all.

Method How it works Strengths Weak points
Security key A small physical key you plug in or tap against the phone Strongest protection; will not work on a fake site Costs money; buy two in case you lose one; not supported everywhere
Passkey Your phone or computer confirms it is you with your face, fingerprint or screen lock Phishing-resistant and easy once set up Not offered everywhere yet; stored on your device or synced through its cloud keychain or password manager
Authenticator app An app shows a six-digit code that changes every 30 seconds Works without signal; not tied to your phone number Codes can be typed into a fake page; lost with the phone unless backed up
App prompt An “Is it you trying to sign in?” notification on a phone already signed in One tap, no codes to type; safer when it asks you to match a number Plain Yes/No prompts are easy to approve by habit when an attacker sends them repeatedly
Text or voice code A code arrives by SMS or automated call Works on any phone; nothing to install SIM-swap fraud can divert your number; texts can be delayed abroad

SIM-swap fraud is the main reason text codes rank last. A criminal persuades your mobile network to move your number to their SIM card, then receives your codes. It takes effort and some of your personal details, so it is far rarer than simple password attacks, but it happens. Microsoft, calling SMS “a leading source of fraud”, has started phasing out text codes for personal Microsoft accounts in favour of passkeys.

Five bars rising from text message to security key, with authenticator app and prompt level in the middle
Every method here blocks a stolen password on its own; only passkeys and security keys also refuse to work on a fake login page.

Why your email account comes first

Almost every “forgot password” link sends a reset to your email. Whoever controls your inbox can therefore reset your other accounts and delete the confirmation emails before you see them, which is why the NCSC singles out email as the account to protect first.

If you have several email addresses, start with the one your bank and online shops use. Then do the account that controls your phone, your Apple Account or Google Account, because it holds your backups, photos and the ability to locate or erase the device. On many Android phones and for Gmail users, these are the same account, which saves a step.

Envelope icon at the centre with key-marked lines out to bank, shopping, social, photos, phone and laptop icons
Your inbox is the reset route for most other accounts, so protecting it protects them indirectly.

Where the setting lives on the big platforms

These paths were correct in September 2026. Companies rename menus regularly, so if one has moved, search the account’s settings for “2-step” or “two-factor”.

Google (Gmail, Android, YouTube)

  1. Go to your Google Account, on a computer at myaccount.google.com or on Android in Settings → Google → Manage your Google Account.
  2. Open Security & sign-in, then under How you sign in to Google, select Turn on 2-Step Verification.
  3. Follow the prompts. Google prompts and passkeys are its recommended options; add an authenticator app or phone number as backup.

Apple Account

Two-factor authentication is already the default for most Apple Accounts. To check, go to Settings → [your name] → Sign-In & Security. If it is off, tap Turn On Two-Factor Authentication. While you are there, make sure your trusted phone numbers are current and consider adding a recovery contact under Recovery Contacts.

Microsoft (Outlook, Windows, Xbox)

  1. Go to account.microsoft.com/security and sign in.
  2. Select Manage how I sign in, then under Additional security, find Two-step verification and choose Turn on.
  3. Microsoft recommends having three pieces of security info on the account, such as an authenticator app and a backup email address.

Facebook and Instagram

Both use Meta’s Accounts Centre, which you reach from the settings menu in either app. Open Accounts Centre → Password and security → Two-factor authentication, choose the account and pick a method. An authenticator app is a better choice than text messages here, and you can generate a set of recovery codes on the same screen.

WhatsApp

WhatsApp registers by phone number, so its extra step is something you choose rather than a code sent to you. Go to Settings → Account → Two-step verification → Turn on (or Set up PIN) and add an email address so you can reset it if you forget. For years this was a six-digit PIN; from August 2026 WhatsApp began replacing it with a longer password, so if your app offers a password, use it. Our guide to recovering a hacked WhatsApp account explains why this step matters so much.

Amazon

Go to Your Account → Login & security, find 2-step verification and follow the option to turn it on. Amazon offers text codes or an authenticator app; choose the app and keep the phone number as a backup.

For banks, the second step is usually built into the banking app, which asks you to approve payments and new devices. In the UK, strong customer authentication rules already require an extra check on many online card payments. Check the app’s security settings anyway, and make sure the phone number the bank holds is your current one.

Phone on a round cafe table showing six-digit codes with countdown rings for email, bank, shop and other accounts
An authenticator app generates a fresh code every 30 seconds, even with no phone signal.

Your one-evening plan

Work down this list in order, doing each account fully, including its backup step, before moving on. Most take five to ten minutes. If you run out of time, the first three rows cover the accounts that can unlock everything else.

Order Account Method to choose Backup step before moving on
1 Main email (the one your bank uses) Prompt, passkey or authenticator app Save backup codes; check recovery phone and email are current
2 Apple Account or Google Account on your phone Built-in prompts or trusted device codes Add a second trusted number or recovery contact
3 Password manager, if you use one Authenticator app or security key Store its recovery key or emergency kit on paper
4 Online banking The bank’s own app approval Write down the fraud number from the back of your card
5 Facebook and Instagram Authenticator app Save the recovery codes
6 WhatsApp Two-step PIN or password Add a recovery email address
7 Amazon and other shops with your card saved Authenticator app Keep your phone number as a second method
8 Microsoft account, if you use Windows or Outlook Authenticator app or passkey Add a backup email address
Evening room with a window and wall clock above a shelf of account icons, five ticked off and three still to do
Doing the accounts in order means the most important ones are protected even if you stop halfway.

Backup codes: where to keep them

When you turn on 2FA, most services offer a set of one-time backup codes. Google, for example, gives you ten eight-digit codes, each of which works once. They are your way back in if your phone is lost, broken or stolen, so they must not live only on that phone.

  • A password manager works well, as long as the manager itself is not locked behind the phone you might lose.
  • A printed sheet kept with your passport or other important papers is simple and hard for an online attacker to reach.
  • Not a screenshot in your photo library, a note in your email or a message to yourself. If someone gets into those, the codes go with them.

Label each set with the account name and the date. If you generate new codes later, the old set stops working, so replace the sheet.

Printed sheet of backup codes half inside a document folder next to a passport-style booklet
A printed set of backup codes kept with your important papers is out of reach of anyone attacking you online.

When you change or lose your phone

This is where people lock themselves out. Text codes follow your number to a new phone, but authenticator app codes only move if you move them. Do this while the old phone still works.

  • Google Authenticator can sync codes to your Google Account, so signing in on the new phone brings them across. Without sync, use Transfer accounts → Export accounts on the old phone and Import accounts on the new one to scan a QR code.
  • Microsoft Authenticator has a cloud backup option, but backups only restore to the same type of phone. Moving from Android to iPhone, or back, means re-adding accounts.
  • Other authenticator apps vary. Check for a backup or export option before you need it.

After moving, sign in to your email on the new phone using the new codes before you erase the old one. Our guide to wiping a phone before you sell it covers the rest of that checklist. If a phone is lost with no backup, use your saved backup codes, then set up the authenticator again from scratch.

Old phone showing an export QR code beside a new phone scanning it on top of its open box
Move authenticator codes while the old phone still works, then test a sign-in before wiping it.

Setting it up for an older relative

2FA protects older people from exactly the account takeovers that target them, but a method they find confusing will get switched off. Do it together, with their agreement, on their own phone.

  • Pick the simplest method they will actually use. A prompt on their phone, or a text code, is often better than an authenticator app they will not open.
  • Print their backup codes and put them with their important papers, not in your house.
  • Offer to be a recovery contact where the service supports it, such as Apple’s Recovery Contacts. You can help them regain access, but you cannot see their account.
  • Agree the one rule: “Nobody genuine will ever ask you to read out a code or tap Yes for them. If anyone does, hang up and ring me.”

That last sentence is worth writing on a card beside the phone. Scammers who have a password often call pretending to be the bank or the phone company, precisely to talk someone into sharing the code.

Side table with a phone showing a sign-in code text, reading glasses, tea and a card saying never read out a code
A single rule on a card by the phone does more for an older relative than the most secure method they will not use.

If codes don’t arrive or you get locked out

  • Text codes never arrive. Check signal and that the number on the account is current. Abroad, texts can be slow; use an authenticator app or backup code instead.
  • Authenticator codes are rejected. The phone’s clock may be wrong. Turn on automatic date and time in the phone’s settings.
  • You get prompts you did not trigger. Tap No, then change that account’s password at once. Someone has it.
  • You are fully locked out. Use the service’s official account recovery page, reached by typing its address yourself. Recovery can take days, and no genuine support agent will contact you first offering to speed it up.

Frequently asked questions

Will I have to enter a code every time I sign in?

Usually not. Most services ask for the second step on a new device or browser, then remember that device. You will be asked again after clearing cookies or signing in somewhere new.

Is a text message code really worth it if it can be intercepted?

Yes. Most account attacks use stolen passwords at scale and never get as far as a SIM swap. A text code stops those. Upgrade to an app or passkey when the service offers one.

What is the difference between 2FA, 2SV and MFA?

For everyday purposes they mean the same thing: signing in needs more than a password. MFA, multi-factor authentication, is the broader term that allows more than two steps.

Do passkeys replace two-factor authentication?

A passkey combines something you have, your device, with your fingerprint, face or screen lock, so it counts as strong verification on its own. Keep a backup method on the account in case you lose access to the device.

Can I use one authenticator app for all my accounts?

Yes. Any standard authenticator app works with most services that offer app codes, so you can keep them all in one place. Just make sure that app is backed up.

Sources and further reading

Using a monitoring app for this? TheTruthSpy is a free parental control app for Android that stays visible on the child's phone. If it fits your family, see what the app does.

Free parental control app for Android

GPS tracking, screen time limits, web filtering, SMS and call monitoring — visible on your child's phone. Pair a phone in about ten minutes.

Android · Free to set up · Visible on your child's phone