Turning on two-step sign-in
Two-step sign-in asks for a second proof, like a code or your fingerprint, so a stolen password isn't enough. Turn it on for email, banking and anything important.
You'll need
- Your phone
- Your account logins
Do it like this
- Open the account's settings. Look for Security, or Password and Security (CISA).
- Find two-factor authentication, two-step verification or multifactor authentication (CISA).
- Pick a method: an authenticator app, a code by text or email, or biometrics (CISA). If offered, passkeys, security keys or authenticator apps are stronger (National Cybersecurity Alliance).
- Save the backup codes it gives you in your password manager.
- Do email first, then bank, then everything else that offers it (CISA).
Watch out. Never read a sign-in code to someone who calls or texts you. Scammers use phishing to trick people into giving up login credentials (FTC).
If it doesn't work
- New phone? Move your authenticator app before you wipe the old one, or use your saved backup codes.
- Locked out? Use a backup code or the account's official recovery process. Don't use a "recovery service" that contacts you.
- Account doesn't offer it? CISA suggests asking them why not (CISA).
Good to know
Why it works
Even if someone has your username and password, they can't log in without the second factor (FTC).
Authenticator apps
These apps make a new code every 30 seconds (CISA).
Passkeys
Passkeys use a key stored on your device plus your fingerprint or face, and can't be guessed or reused (National Cybersecurity Alliance).
Sources
- Cybersecurity and Infrastructure Security Agency Turn on MFA
- Federal Trade Commission Use two-factor authentication to protect your accounts
- National Cybersecurity Alliance Multi-factor authentication
Lesson T2.2 · Last checked October 2, 2026 against the sources listed. See a mistake?
Find it online: