Dwight Pavlovic | November 17, 2021

How to Set Up Two-Factor Authentication

How to Set Up Two-Factor Authentication

A username and password are no longer enough to protect many online accounts. Passwords can be guessed, reused, stolen in phishing attacks or exposed during a data breach. Two-factor authentication, commonly called 2FA, adds another verification step to help prevent unauthorised access.

Two-factor authentication is usually quick to set up and can protect email, banking, cloud storage, social media, workplace and government accounts. This guide explains how 2FA works, which methods are most secure and how to set it up without losing access to your account.

What Is Two-Factor Authentication?

Two-factor authentication requires two different types of evidence when you sign in:

  • Something you know: A password or PIN.

  • Something you have: A smartphone, authenticator app, security key or registered device.

  • Something you are: A fingerprint, facial scan or another biometric characteristic.

A password and username do not count as two factors because both are forms of information you know. A password plus a code from an authenticator app is an example of two-factor authentication.

Two-factor authentication is a form of multifactor authentication (MFA). MFA is the broader term for using two or more authentication factors.

Which 2FA Method Should You Choose?

The available options vary by account, but common methods include:

Authenticator apps

An authenticator app generates time-based, one-time codes. It does not always require mobile service, making it useful when travelling or when text messages are delayed.

Security keys

A hardware security key connects through USB, NFC or Bluetooth and provides strong protection against many phishing attacks. Security keys are particularly useful for administrators, business leaders and people with access to sensitive information.

Push notifications

A service sends an approval request to a registered device. This is convenient, but do not approve a sign-in that you did not initiate. Attackers may repeatedly send requests in the hope that you accept one by mistake.

Text messages

SMS codes are widely available and better than using a password alone, but they are more vulnerable to SIM-swap and phone-number attacks. Use an authenticator app or security key when an account supports it.

Biometrics

Fingerprints and facial recognition can make sign-in easier. Biometrics are usually used with a device or passkey rather than as a standalone replacement for every other security control.

Two Factor Authentication

Prepare Before Enabling 2FA

Before changing account settings:

  1. Confirm that you can access the account and its recovery email.

  2. Install the official authenticator app from your device’s app store.

  3. Make sure your phone or security key is available.

  4. Save the account’s recovery codes in a secure location.

  5. Add a second approved recovery method if the service supports one.

  6. Keep your current sign-in method until the new method has been tested.

Do not save recovery codes in an unprotected document on the same device you use to sign in. A password manager, encrypted storage or a secure physical location may be appropriate.

How to Set Up 2FA for a Microsoft Account

Microsoft calls this feature two-step verification. The menu names may change slightly as account settings are updated.

  1. Sign in to your Microsoft account.

  2. Open the Security section at account.microsoft.com/security.

  3. Select Manage how I sign in or the available advanced security option.

  4. Find Two-step verification and select Turn on.

  5. Choose an authenticator app, phone number or another supported verification method.

  6. If using an authenticator app, scan the QR code or enter the setup key manually.

  7. Enter the code generated by the app to confirm the setup.

  8. Save the recovery code and add another recovery method if available.

Microsoft provides current instructions for turning two-step verification on or off in its official support guide.

After setup, test the process in a private browser window or on another trusted device. Confirm that you can complete sign-in and retrieve your recovery information.

How to Set Up 2FA for a Google Account

To enable Google two-step verification:

  1. Sign in to your Google Account.

  2. Open Security.

  3. Under How you sign in to Google, select 2-Step Verification.

  4. Select Get started.

  5. Follow the prompts to register a phone, authenticator app, passkey or security key.

  6. Complete a test sign-in.

  7. Download or record your backup codes and store them securely.

Google’s official instructions provide the current setup flow for Android and other devices. Review your signed-in devices and remove any that you no longer recognise.

How to Set Up 2FA for an Apple Account

On an iPhone or iPad:

  1. Open Settings.

  2. Tap your name.

  3. Select Sign-In & Security.

  4. Tap Turn On Two-Factor Authentication.

  5. Follow the onscreen instructions and confirm a trusted phone number.

On a Mac:

  1. Open the Apple menu.

  2. Select System Settings.

  3. Choose your name.

  4. Open Sign-In & Security.

  5. Select the option to turn on two-factor authentication.

Windows Hello and Device Sign-In

Windows Hello can provide a convenient way to sign in to a compatible Windows computer using a device-bound PIN, fingerprint or facial recognition. A Windows Hello PIN is tied to a specific device and is different from the account password.

However, Windows Hello device sign-in is not automatically the same as enabling 2FA for every online account. Set up 2FA separately for Microsoft, Google, Apple, workplace and other important accounts.

To configure Windows Hello:

  1. Open Settings.

  2. Select Accounts.

  3. Choose Sign-in options.

  4. Select Windows Hello PIN, fingerprint or facial recognition.

  5. Follow the prompts to complete setup.

Your computer must have compatible hardware for fingerprint or facial recognition features. Availability varies by device.

Protect Your Recovery Options

Recovery details are essential if your phone is lost, replaced or unavailable. Add a secondary email address, trusted phone number, backup codes or another security key where supported.

Do not share authentication codes with anyone. Legitimate companies will not ask you to read a one-time code to an unsolicited caller. If you receive an unexpected approval request, deny it, change your password and review recent account activity.

If you lose your authenticator device, use a saved recovery code or another registered method. Contact the service through its official website if you cannot recover the account.

Should You Turn Off 2FA?

In most cases, leaving 2FA enabled is safer than disabling it. If you must remove a method, first add and test another one.

To turn off 2FA, open the account’s security settings, select the two-step or multifactor authentication option and follow the provider’s instructions. Do not simply delete the authenticator app before removing the account registration or adding another recovery method.

Frequently Asked Questions

Is two-factor authentication worth using?

Yes. It adds protection if your password is stolen or reused elsewhere. It cannot prevent every attack, but it makes unauthorised access more difficult.

Which is safer: SMS or an authenticator app?

An authenticator app is generally preferable to SMS because it is less exposed to phone-number takeover. A hardware security key or passkey may provide even stronger phishing resistance.

Can 2FA stop phishing?

Not always. Attackers may try to trick you into sharing a code or approving a fraudulent login. Never enter a code into a page reached through a suspicious message, and never approve an unexpected sign-in request.

Conclusion

Two-factor authentication is one of the most practical ways to strengthen online account security. Start with your primary email account, password manager, financial services, workplace accounts and cloud storage.

Choose an authenticator app, passkey or security key when available, save recovery codes securely and test the setup before relying on it. For computers used at home or work, combine account-level MFA with updates, encryption, automatic screen locking and built-in security features available through HP Canada.

About the Author

Dwight Pavlovic is a contributing writer for HP® Tech Takes. Dwight is a music and technology writer based out of West Virginia.

Disclosure: