What multi-factor authentication does and why it matters

Multi-factor authentication (MFA) adds a second or third checkpoint when you sign in — so even if someone has your password, they cannot get into your account without that second factor. The most common second factor is a code that appears only on your phone, either through an app, a text message, or a push notification you approve.

The reason this matters: passwords alone are not enough. They get stolen from data breaches, guessed through social engineering, or captured by malware. A second factor stops an attacker cold, because they would need physical access to your phone or email to pass that second checkpoint. This is why banks, email providers, and social platforms all offer it — and why security researchers recommend turning it on for accounts that matter.

You do not need to enable MFA everywhere at once. Start with the accounts that would hurt most if someone broke in: email, banking, and work accounts. Those are the keys to resetting passwords on everything else.

Key Takeaways

  • MFA requires a second factor — usually a code from an app or text — when you sign in, so a stolen password alone cannot open your account.
  • Start with email, banking, and work accounts, because those can be used to reset passwords on your other accounts.
  • Authenticator apps like Google Authenticator, Microsoft Authenticator, or Authy are more secure than text messages, because text messages can be intercepted.
  • Save your backup codes in a safe place when you first enable MFA — they let you sign in if you lose access to your phone.
  • You will need to re-enter your password and confirm your identity the first time you turn MFA on, and you may need to sign out and back in on your devices.

Choosing between authenticator apps, text messages, and other methods

Most services offer you a choice of second factors. Authenticator apps are the most secure option. Google Authenticator, Microsoft Authenticator, and Authy all work the same way: you scan a QR code when you set up MFA, and the app generates a new six-digit code every 30 seconds. You type that code into the website or app when you sign in. Because the code is generated on your phone and never sent over the internet, it cannot be intercepted.

Text message codes (also called SMS) are easier to use but less secure. The code is sent to your phone as a text, which you type in. Text messages can be intercepted by someone who has compromised your phone number or your carrier account, though this is rare. If a service offers both, choose the app.

Some services also offer push notifications: your phone gets a notification asking "Is this you signing in?" and you tap yes or no. This is convenient and secure, because you can see where the sign-in is happening and reject it if it is not you. Use this if it is available.

Avoid security questions as a second factor if you have a choice. The answers are often public or easy to guess, and they do not provide real protection.

How to turn on MFA for Gmail and other Google accounts

Go to myaccount.google.com and sign in. On the left side, click Security. Scroll down to "How you sign in to Google" and click 2-Step Verification. Click get your free guide.

Google will ask you to confirm your password and your recovery phone number. Then it will ask you to choose your second factor: an authenticator app, a text message, or a phone call. If you choose an app, Google will show you a QR code. Open Google Authenticator, Microsoft Authenticator, or Authy on your phone, tap the plus button, and scan the code. The app will add your Google account and start generating codes.

Google will ask you to enter a code from your app to confirm it is working. After you do, Google will show you a list of backup codes — usually 10 eight-digit numbers. Save these codes in a safe place, like a password manager or a printed list in a locked drawer. If you lose your phone, these codes let you sign in and regain access to your account.

After you finish, Google will ask you to confirm 2-Step Verification is on. You are done. The next time you sign in on a new device, you will need to enter a code from your app.

How to turn on MFA for Microsoft and Outlook accounts

Go to account.microsoft.com and sign in. Click Security at the top. Under "Security basics," click Two-step verification. Click Set up two-step verification.

Microsoft will ask you to choose how to receive codes: through the Microsoft Authenticator app, a text message, or a phone call. If you choose the app, download Microsoft Authenticator on your phone, open it, and tap the plus button. Select "Work or school account" and sign in with your Microsoft email. The app will add your account and start generating codes.

Microsoft will send you a code to confirm the app is working. Enter it, and you are done. Microsoft does not show backup codes the same way Google does, but you can generate them later by going back to the same page and clicking "Get backup codes." Save them in a safe place.

How to turn on MFA for Facebook and Instagram

Go to facebook.com and sign in. Click the menu icon (three horizontal lines) at the top right. Scroll down and click Settings & Privacy, then Settings. On the left, click Security and Login. Scroll down to "Two-Factor Authentication" and click Edit.

Facebook will show you options: an authenticator app, text messages, or security keys (if your phone supports them). Choose an authenticator app if you can. Facebook will show you a QR code. Scan it with Google Authenticator, Microsoft Authenticator, or Authy. Enter the code the app generates to confirm, and you are done.

Facebook will show you backup codes. Download or print them and store them safely. If you lose your phone, you can use these codes to sign in.

How to turn on MFA for your bank and financial accounts

The steps vary by bank, but the process is similar. Sign in to your bank's website or app. Look for a section called "Security," "Account Settings," or "Preferences." Find the option for two-factor authentication, two-step verification, or multi-factor authentication. Click it.

Your bank will ask you to confirm your identity — usually by answering security questions or entering a code sent to your phone. Then it will ask you to choose a second factor. Most banks offer text messages and authenticator apps. Choose the app if it is available.

If your bank offers it, also look for the option to add a security key — a small physical device that you plug into your computer or tap to your phone. Security keys are the most secure option because they cannot be phished or intercepted. If your bank supports them and you want maximum protection, consider buying one (they cost $20 to $50).

Save your backup codes. If your bank does not show them automatically, ask customer service where to find them.

What to do if you lose your phone or cannot access your second factor

This is why backup codes matter. If you lose your phone or your authenticator app stops working, sign in with your password and then enter one of your backup codes instead of the code from your app. Each backup code works only once, so use them one at a time.

If you have lost your backup codes and cannot access your second factor, you will need to contact the service's support team. They can verify your identity through other means — security questions, a code sent to your email, or a video call — and turn off MFA temporarily so you can sign in and set it up again on a new phone.

This is why it is important to save your backup codes as soon as you enable MFA. Do not wait until you need them.

Frequently Asked Questions

Do I have to use an authenticator app, or can I just use text messages?

You can use text messages if that is all the service offers, but authenticator apps are more secure. Text messages can be intercepted if someone compromises your phone number or your carrier account. Apps generate codes on your phone that never leave it, so they cannot be intercepted. If a service offers both, choose the app.

What if I get a new phone?

Before you switch phones, sign into your authenticator app on your old phone and look for an option to export or back up your accounts (Google Authenticator does not have this, but Authy and Microsoft Authenticator do). On your new phone, download the same authenticator app and restore your accounts. If you cannot restore them, you can re-add each account by scanning the QR code again — most services let you generate a new QR code in your security settings. You will not lose access to your accounts as long as you have your backup codes.

Can someone hack my authenticator app?

An authenticator app on your phone is very difficult to hack because it does not connect to the internet — it generates codes locally. Someone would need physical access to your phone and would have to unlock it. If your phone is stolen, the thief could potentially use your authenticator app to sign into your accounts, which is why a strong phone password or biometric lock (fingerprint or face recognition) matters.

What is the difference between MFA and two-factor authentication?

Two-factor authentication (2FA) means exactly two factors — your password plus one other thing. Multi-factor authentication (MFA) means two or more factors, so it includes 2FA but can also mean three or more. In practice, most people use the terms interchangeably, and most services offer two factors: your password and an authenticator app or text message.

Do I need to set up MFA on my phone for my phone accounts?

Yes. Even though you are signing in on the device that has your authenticator app, you should still enable MFA. If someone steals your phone or compromises it with malware, MFA will still protect your accounts. The code will be generated on the same phone, but an attacker would still need to know your password and would have to unlock your phone to see the code.