Digital Safety & Privacy

Two-Factor Authentication: Methods, Setup Order, and Recovery Codes

Compare security keys, authenticator apps, push prompts, biometrics, and codes, then protect important accounts without creating a lockout.

What this guide helps you do

Enable suitable multifactor authentication on priority accounts and preserve a safe recovery path.

Two-factor or multifactor authentication requires another form of verification in addition to a password. It can prevent a stolen password from becoming a complete account takeover, but method strength, enrollment, prompts, recovery, and support procedures determine how well it works.

Know the difference between steps and factors

A factor may be something you know, have, or are. Two passwords are two steps but the same factor type. Services use “2FA” and “MFA” differently, so focus on the actual method and recovery path rather than the label.

Compare common methods

MethodBenefitWatch for
Security key or passkeyCan resist many phishing attacksDevice support, spare key, recovery
Authenticator app codeWorks without cellular deliveryDevice loss, seed backup, fake prompts
Number-matching pushConvenient with contextPrompt fatigue and inattentive approval
SMS or email codeWidely availableWeaker delivery and account-recovery paths
Biometric unlockConvenient local verificationOften unlocks a device-held credential rather than replacing recovery

Use the strongest method the account and your devices reliably support. CISA recommends moving toward phishing-resistant MFA for higher-value business access.

Prioritize accounts by blast radius

Start with primary email, password manager, financial accounts, cloud storage, mobile carrier, domain registrar, social accounts, work systems, and administrator access. Email often controls password resets; protecting it improves recovery for many other services.

Enroll from a trusted session

  1. Navigate through the official app or typed address.
  2. Review and remove unknown sessions and recovery methods.
  3. Add the chosen method.
  4. Register a backup method appropriate to the risk.
  5. Generate and store recovery codes offline.
  6. Sign out and test a normal login.
  7. Test the documented recovery path without consuming the only code.

Protect recovery codes and backup methods

Recovery codes can bypass the normal second factor. Store them in a protected offline location or suitable password-manager record, not beside the unlocked device. For organizations, define who may recover an account, what identity proof is required, and how recovery events are logged and reviewed.

Never approve an unexpected prompt

Deny it, then open the account through a trusted path, change the password, review sessions, and contact support or security if needed. Repeated prompts can mean someone already has the password. Do not share a one-time code with a caller or person claiming to be support.

Plan for a lost or replaced phone

Before replacing a device, transfer supported authenticators, confirm a second method, and retain recovery codes. Do not erase the old device until important accounts work on the new one. When a device is lost, revoke it and review sessions rather than relying only on its screen lock.

Review enrolled methods periodically

Remove old phones, unknown security keys, unused app connections, obsolete phone numbers, and former employee access. Confirm recovery contacts and backup codes after an account or device change. For organizations, report enrollment coverage separately from successful enforcement and test that privileged and remote access cannot bypass the required method.

Use 2FA with unique passwords

MFA is an extra layer, not permission to reuse passwords. Create unique credentials with the password-manager setup guide. If an enrollment or recovery message arrives unexpectedly, follow the phishing verification process before clicking.

Sources and further reading

Primary and contextual sources used to verify definitions or give readers a relevant next resource.

IE

Prepared and reviewed by

Infortified Editorial Team

Research-led guides with explicit scope, source checks where facts require them, and an independence review before publication.

Search Infortified

Find a practical answer

Start typing to search all guides.

Open full search