Privacy › Module 2 › Lesson 2
Two-Factor Authentication Setup
Enable two-factor authentication and choose the strongest second factors available
Opening
Password stolen? 2FA can still stop them
Two-factor authentication (2FA), also called multi-factor authentication (MFA), requires a second proof after your password. Even if an attacker guesses or buys your password, they still need your phone, security key, or authenticator app. Turn on 2FA everywhere it matters: email, banking, cloud storage, and work accounts.
1. Common Second Factors
From strongest to weakest for most users:
Hardware security keys (FIDO2/WebAuthn)
USB or NFC keys like YubiKey. Phishing-resistant because the key checks the real site domain.
Authenticator apps (TOTP)
Apps like Google Authenticator, Microsoft Authenticator, or Aegis generate rotating 6-digit codes. Better than SMS because codes are not intercepted over the phone network.
Push approvals
Tap Approve in an app. Convenient, but watch for push fatigue—only approve logins you initiated.
SMS text codes
Better than nothing, but vulnerable to SIM swap attacks. Use only when stronger options are unavailable.
2. How to Enable 2FA
Open account Security or Sign-in settings. Choose authenticator app or security key when offered. Scan the QR code with your authenticator, save backup codes in your password manager, and test login once before logging out. For work or school SSO, your IT team may require a specific method—follow their policy.
3. Backup Codes and Recovery
When you enable 2FA, you usually receive one-time backup codes. Store them offline in your password manager or a printed copy in a safe place. If you lose your phone, backup codes are how you get back in without support tickets—covered more in the next lesson.
Prioritize email first
Your email account resets passwords for other services. Secure email with a strong password, 2FA, and a hardware key or authenticator before anything else.
Knowledge Check
2FA means an attacker needs:
Multiple choice
Knowledge Check
Which second factor is generally most phishing-resistant?
Multiple choice
Knowledge Check
True or False: You should save 2FA backup codes when you enable two-factor authentication.
True or False