Two-factor authentication guide: which method to use, and where to start

Password & accounts. Updated 2026-09-13. About 5 minutes to read.

Turn on two-factor authentication for your email account today, use a passkey or authenticator app instead of text messages, and save your backup codes offline.

Two-factor authentication means a stolen password is not enough to get into your account. The attacker also needs a second thing, such as a code from your phone, a tap on a security key or your face or fingerprint on a passkey. Any second factor stops most mass attacks on reused passwords.

The methods are not equal. Text message codes and app codes can be phished in real time, while passkeys and hardware security keys cannot. This guide ranks the options, explains passkeys in plain terms and gives you a setup order that protects the accounts that matter first.

The options, from weakest to strongest

  • Text message or voice codes: easy and widely offered, but vulnerable to SIM swaps and phishing sites that relay the code.
  • Email codes: only as strong as your email account's own protection.
  • Authenticator app codes, such as Google Authenticator, Microsoft Authenticator, 2FAS, Aegis or Ente Auth: not tied to your phone number, but a fake site can still ask you to type the code.
  • Push approval with number matching: you type a number shown on the login screen into the app, which defeats blind approve-spam attacks.
  • Passkeys: a sign-in credential stored on your device or password manager, approved with your face, fingerprint or PIN, and tied to the real website.
  • Hardware security keys: a physical FIDO key you tap or plug in. CISA calls FIDO the only widely available phishing-resistant authentication.

Why text message codes are weak, but better than nothing

A criminal who convinces your carrier to move your number to their SIM receives your codes. A phishing page can also ask for the code and use it within seconds. That is why NIST's digital identity guidelines treat phone network codes as a restricted method.

Still, text codes stop the huge volume of attacks that simply try leaked passwords. If a site only offers text codes, turn them on, and add a port-out lock with your carrier.

Passkeys: why a fake site gets nothing

A passkey is a pair of cryptographic keys. The website keeps the public half. The private half stays on your phone, computer or password manager, and you approve each sign-in with the same face, fingerprint or PIN you use for the device. Nothing reusable is typed or sent.

Your device only uses a passkey on the website it was created for. A look-alike domain cannot ask for it, so there is nothing for a phishing page to capture. That is the property text and app codes lack. Passkeys that sync through Apple, Google or a password manager also survive losing one device.

Setup order: protect the accounts that matter first

  1. Primary email account, because it resets everything else.
  2. Your password manager, if you use one.
  3. Your Apple Account, Google Account or Microsoft account, which control your devices, backups and saved passwords.
  4. Bank, brokerage, super or pension, and payment apps such as PayPal.
  5. Your mobile carrier account, where you also set a port-out PIN or number lock.
  6. Social media and shopping accounts that store cards.
  7. Everything else, as you next log in.

Set it up without locking yourself out

  1. Add at least two methods on each important account, such as a passkey and an authenticator app, or two security keys.
  2. Download or print the backup codes and store them offline, with your important papers, not in your email.
  3. Before logging out, test the new method by signing in from a private browser window.
  4. If you move your authenticator app to a new phone, transfer the codes before wiping the old phone.
  5. Review the trusted devices list on each account once a year and remove old ones.

Losing your only second factor with no backup codes can mean losing the account for good. Set up the backup before you need it.

Security keys and Advanced Protection for high-risk people

Journalists, activists, political staff, executives and anyone being targeted should consider hardware keys. Apple's Security Keys for Apple Account need at least two FIDO Certified keys and iOS 16.3, iPadOS 16.3 or macOS Ventura 13.2 or later. On an iPhone, add them in Settings, tap your name, then Sign-In and Security, then Two-Factor Authentication, then Security Keys.

Google's Advanced Protection Program can be enrolled with passkeys or security keys. It lets only Google apps and verified third-party apps access your data, and account recovery takes extra steps. That friction is the point.

Choosing an authenticator app

  • Google Authenticator and Microsoft Authenticator: widely supported, with optional backup to your Google or Microsoft account.
  • 2FAS: free and open source on iPhone and Android.
  • Aegis: free, open source and Android only, with encrypted local backups.
  • Ente Auth: free, open source, and syncs encrypted codes across platforms.
  • Your password manager's built-in code generator: convenient, but it puts both factors in one place, so keep email and the manager itself on a separate method.

Frequently asked questions

Is text message two-factor authentication better than nothing?

Yes. It blocks most automated attacks using leaked passwords. It is the weakest option, so switch to an authenticator app, passkey or security key wherever the site offers one.

What happens if I lose the phone with my authenticator app?

Use a backup code or your second method to sign in, then set up the app again on the new phone. If the app backed up to your Google or Microsoft account, restore it there. Without any backup, you face each site's account recovery process.

Are passkeys the same as two-factor authentication?

A passkey combines something you have, your device, with something you are or know, your face, fingerprint or PIN. Many sites treat it as a replacement for both the password and the second factor, and it resists phishing better than codes.

Should I keep two-factor codes in my password manager?

For ordinary accounts, it is convenient and much better than no second factor. For your email and the password manager itself, keep the second factor separate, such as a security key or authenticator app.

Do I really need a hardware security key?

Most people do not. Passkeys give similar phishing resistance with the devices you already own. Hardware keys make sense if you are a likely target or want a backup that does not depend on your phone.

Tools that help

Related guides

Sources