Add another proof of access
Multifactor authentication asks for more than a password, using supported factors such as an authenticator or security key. Two different passwords alone do not create two independent factor types.
Compare the available methods
Methods differ in phishing resistance and recovery behaviour. Use the strongest suitable option the service supports; do not assume a text code and a security key offer identical protection.
Prepare for device loss
Store recovery codes securely and check the process for replacing a phone or key. Confirm access before removing the previous method. Keep a second supported recovery route where appropriate.
Treat unexpected prompts cautiously
Do not approve sign-ins you did not initiate or share one-time codes with an unexpected caller. Multifactor authentication reduces some risks but cannot guarantee safety after a device compromise or fraudulent approval.
Questions about this guide
What should I save when enabling two-factor authentication?
Follow the service's recovery guidance and keep backup codes securely where you can reach them if your usual device is lost. Test the sign-in process before signing out everywhere.
Should I approve an authentication prompt I did not request?
Do not approve it. Open the service independently, review account activity and change compromised credentials as appropriate; never give an unexpected caller your authentication code.