C

Privacy › Module 2 › Lesson 2

BeginnerModule 2Lesson 2/4

Two-Factor Authentication Setup

Enable two-factor authentication and choose the strongest second factors available

15 min+38 XP3 quiz
Module progress2 of 4
Vault · Password lock · Smartphone authenticator

Opening

Password stolen? 2FA can still stop them

Two-factor authentication (2FA), also called multi-factor authentication (MFA), requires a second proof after your password. Even if an attacker guesses or buys your password, they still need your phone, security key, or authenticator app. Turn on 2FA everywhere it matters: email, banking, cloud storage, and work accounts.

1. Common Second Factors

From strongest to weakest for most users:

  • Hardware security keys (FIDO2/WebAuthn)

    USB or NFC keys like YubiKey. Phishing-resistant because the key checks the real site domain.

  • Authenticator apps (TOTP)

    Apps like Google Authenticator, Microsoft Authenticator, or Aegis generate rotating 6-digit codes. Better than SMS because codes are not intercepted over the phone network.

  • Push approvals

    Tap Approve in an app. Convenient, but watch for push fatigue—only approve logins you initiated.

  • SMS text codes

    Better than nothing, but vulnerable to SIM swap attacks. Use only when stronger options are unavailable.

2. How to Enable 2FA

Open account Security or Sign-in settings. Choose authenticator app or security key when offered. Scan the QR code with your authenticator, save backup codes in your password manager, and test login once before logging out. For work or school SSO, your IT team may require a specific method—follow their policy.

3. Backup Codes and Recovery

When you enable 2FA, you usually receive one-time backup codes. Store them offline in your password manager or a printed copy in a safe place. If you lose your phone, backup codes are how you get back in without support tickets—covered more in the next lesson.

Prioritize email first

Your email account resets passwords for other services. Secure email with a strong password, 2FA, and a hardware key or authenticator before anything else.

Knowledge Check

1

2FA means an attacker needs:

Multiple choice

Knowledge Check

2

Which second factor is generally most phishing-resistant?

Multiple choice

Knowledge Check

3

True or False: You should save 2FA backup codes when you enable two-factor authentication.

True or False

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)