Two-factor authentication adds another check beyond a password. That extra step can protect an account even when a password is exposed, although different methods have different tradeoffs.

Common authentication methods

Services may offer SMS codes, authenticator-app codes, approval prompts, passkeys, or physical security keys. Availability varies.

Authenticator apps

Many authenticator apps generate time-based codes on your device. They do not rely on receiving a text message, but you need a recovery plan if the device is lost.

Security keys and passkeys

Phishing-resistant methods can provide stronger protection against fake login pages because authentication is linked to the legitimate service. They can be particularly valuable for important accounts.

Recovery codes matter

When a service provides one-time recovery codes, store them somewhere secure and separate from the device you normally use to sign in.

Never share a verification code

A person asking you to read back a login code may be attempting to complete a sign-in using your credentials. Treat unexpected prompts as a warning and open the official service directly to review activity.

Where to enable protection first

Prioritize your primary email, password manager, financial services, cloud storage, social accounts, and any account capable of resetting other accounts.

Two-factor authentication works best alongside unique passwords, secure recovery options, and careful attention to unexpected login prompts.

Editorial note: Technology changes quickly. Check current product interfaces and official documentation before making important account or security changes.