Enable suitable multifactor authentication on priority accounts and preserve a safe recovery path.
Two-factor or multifactor authentication requires another form of verification in addition to a password. It can prevent a stolen password from becoming a complete account takeover, but method strength, enrollment, prompts, recovery, and support procedures determine how well it works.
Know the difference between steps and factors
A factor may be something you know, have, or are. Two passwords are two steps but the same factor type. Services use “2FA” and “MFA” differently, so focus on the actual method and recovery path rather than the label.
Compare common methods
| Method | Benefit | Watch for |
|---|---|---|
| Security key or passkey | Can resist many phishing attacks | Device support, spare key, recovery |
| Authenticator app code | Works without cellular delivery | Device loss, seed backup, fake prompts |
| Number-matching push | Convenient with context | Prompt fatigue and inattentive approval |
| SMS or email code | Widely available | Weaker delivery and account-recovery paths |
| Biometric unlock | Convenient local verification | Often unlocks a device-held credential rather than replacing recovery |
Use the strongest method the account and your devices reliably support. CISA recommends moving toward phishing-resistant MFA for higher-value business access.
Prioritize accounts by blast radius
Start with primary email, password manager, financial accounts, cloud storage, mobile carrier, domain registrar, social accounts, work systems, and administrator access. Email often controls password resets; protecting it improves recovery for many other services.
Enroll from a trusted session
- Navigate through the official app or typed address.
- Review and remove unknown sessions and recovery methods.
- Add the chosen method.
- Register a backup method appropriate to the risk.
- Generate and store recovery codes offline.
- Sign out and test a normal login.
- Test the documented recovery path without consuming the only code.
Protect recovery codes and backup methods
Recovery codes can bypass the normal second factor. Store them in a protected offline location or suitable password-manager record, not beside the unlocked device. For organizations, define who may recover an account, what identity proof is required, and how recovery events are logged and reviewed.
Never approve an unexpected prompt
Deny it, then open the account through a trusted path, change the password, review sessions, and contact support or security if needed. Repeated prompts can mean someone already has the password. Do not share a one-time code with a caller or person claiming to be support.
Plan for a lost or replaced phone
Before replacing a device, transfer supported authenticators, confirm a second method, and retain recovery codes. Do not erase the old device until important accounts work on the new one. When a device is lost, revoke it and review sessions rather than relying only on its screen lock.
Review enrolled methods periodically
Remove old phones, unknown security keys, unused app connections, obsolete phone numbers, and former employee access. Confirm recovery contacts and backup codes after an account or device change. For organizations, report enrollment coverage separately from successful enforcement and test that privileged and remote access cannot bypass the required method.
Use 2FA with unique passwords
MFA is an extra layer, not permission to reuse passwords. Create unique credentials with the password-manager setup guide. If an enrollment or recovery message arrives unexpectedly, follow the phishing verification process before clicking.
Sources and further reading
Primary and contextual sources used to verify definitions or give readers a relevant next resource.
- CISA multifactor authentication guidance Official comparison and implementation guidance, including stronger phishing-resistant methods.