Two-Factor Authentication Explained: Why It Matters
Multifactor authentication asks for more than a password, using supported factors such as an authenticator or security key.
- Understand what counts as a second factor
- Enable protection in a safe order
- Plan phone replacement and travel
- Reject unexpected approvals and recognise the limits
- Example: replacing a phone without losing work access
- A recovery test before you need it
- Questions about this guide
- Further reading
- Related help
- Terms in this area
- Read next
- Tell us about your own situation.
- Services
- Resources
- Company
- Get in touch
Multifactor authentication asks for more than a password, using supported factors such as an authenticator or security key. A stolen password should not be enough to open your email or cloud files. Two-factor authentication adds a second type of evidence, such as possession of a phone or security key. It reduces account takeover risk, but the method and recovery process matter. The aim is reliable protection you can keep using after a phone replacement, loss or trip. This guide explains the differences between SMS, authenticator codes, approval prompts and phishing-resistant options, then shows how to enable protection without losing access. Understand what counts as a second factor Two passwords are both something you know, so they are not two different factors. A password plus a code generated on a registered device combines knowledge and possession. A biometric may unlock that device or approve a credential; its role depends on the service. SMS can be better than password-only access but depends on the telephone number and can be vulnerable to number takeover or interception. Authenticator codes work without a mobile signal once configured, yet a fake login page can trick you into sharing them. Security keys and appropriately implemented passkeys use the genuine service origin, providing stronger resistance to that credential-relay phishing. Enable protection in a safe order Begin with your main email because it often receives password-reset links. Open the account’s security settings independently, check recovery details and select a supported method. Register your device, complete the requested test and keep the recovery codes according to the service’s guidance. Do not sign out of every existing session until you have tested the new method. Use another browser session to confirm a fresh login works. If you are adding a hardware key, register a spare where the service permits it and store it separately. An employer’s account may have specific policies: do not replace or bypass an organisation’s authentication controls without its administrator. Plan phone replacement and travel An authenticator app is not automatically backed up merely because your photos are in the cloud. Check its documented transfer and backup behaviour. Before wiping the old phone, register the new one or transfer accounts using the supported process, then test access to each important service. Phone-number changes require a separate review of SMS and recovery settings. Keep a rec
What should I save when enabling two-factor authentication?
Follow the service's recovery guidance and keep your backup codes somewhere safe that you can still reach if your usual device is lost. Test the sign-in process before you sign out everywhere.
Should I approve an authentication prompt I didn’t request?
No, please do not approve it. Open the service yourself, look at the account activity and change any compromised credentials. Never give your authentication code to an unexpected caller.
Can a phishing page steal an authenticator code?
Yes, a fake site can ask for the code and pass it on while it is still valid. Phishing-resistant security keys and properly implemented passkeys deal with that risk more directly, and every method still needs secure recovery.