RAZIBINTERNET INDEX Suggest a resource

Account security

How to Choose Two-Factor Authentication You Can Keep Using

Compare passkeys, security keys, authenticator apps and SMS, then set up a second factor with a reliable backup route.

Two-factor authentication is worth setting up before an account gives you a reason to worry. The difficult part is usually not entering an extra code. It is choosing a method that will still work after a phone replacement, a change of number or a journey without mobile service.

Start with the accounts that can reset other accounts: primary email, your password manager and the account used to synchronize your devices. Then work through services containing personal files or important communications. A deliberate setup on these accounts is more useful than turning on a method you do not understand everywhere at once.

Match the method to the account

Account settings may call the feature two-factor authentication, two-step verification or multifactor authentication. They are not promises that every listed method offers identical protection. Read the options offered by the service rather than looking only for an on/off switch.

CISA's introduction to MFA explains the extra verification step that can make a stolen password less useful. Your job is to choose a method you can use consistently and arrange a backup before finishing setup.

For personal accounts, this is a practical comparison:

Method Useful quality What to plan around
Passkey Avoids a reusable password in the supported sign-in flow Know the credential provider and recovery route
Hardware security key Can provide phishing-resistant authentication when used through supported standards Register and protect a spare if the account allows one
Authenticator app Generates codes without relying on text-message delivery Understand backup, migration and device-loss recovery
SMS code Widely available and straightforward Depends on continued control of your number and carrier account

This is a starting point, not a claim that every product in one row behaves the same way.

Prefer phishing resistance when it fits

The FIDO Alliance explains why passkeys are bound to the service they authenticate to. Supported FIDO security-key flows offer a related advantage: you are not handing a reusable six-digit response to whichever page asks for it.

That matters because a fake sign-in page can request a password and an ordinary one-time code together. A code that changes quickly is not automatically resistant to someone relaying it immediately.

Read passkeys versus passwords before switching. A passkey may replace the password-based flow rather than appear as a conventional second step. The service decides which alternatives and recovery paths remain enabled.

For a key, check the ports and wireless methods supported by your real devices. A strong credential that you cannot connect to your phone will encourage shortcuts. Test compatibility before making it your only option.

Set up an authenticator app carefully

Choose an authenticator from its official developer listing. Open the account's security page yourself and follow its setup flow. The QR code shown during enrollment is sensitive because it can encode the secret used to generate future codes.

Do not paste that QR code into a chat, upload it to a public image tool or save an unprotected screenshot in a shared photo library. After scanning, enter the requested confirmation code so the account actually completes enrollment.

Learn whether the app's entries are stored locally, synchronized through an account or exported through a separate backup process. These are product-specific features. A phone backup should not be assumed to restore every authenticator automatically.

For the password manager's own login, think carefully before keeping its only second factor inside that same manager. Convenience is not the problem; having no independent recovery route is. Prepare recovery codes while you still have working access.

Use SMS thoughtfully when it is the available option

Do not leave an important account without a second factor simply because its choices are limited. SMS can still provide a useful barrier beyond a password, but your mobile number becomes part of the security arrangement.

Check that the number is yours, active and likely to remain under your control. Add a carrier account PIN or other anti-transfer protections when available, using the carrier's own instructions. Avoid relying on a temporary travel SIM for long-term recovery.

Google's verification-method guidance discusses options and risks, including attacks against phone-number-based methods. Availability differs between services, accounts and countries, so keep a practical fallback rather than assuming texts always arrive abroad.

Before giving up an old number, update accounts that use it. The same inventory used when changing your email address can track number changes.

Do not approve prompts you did not start

A legitimate-looking approval request is not a command to press Yes. Check the account, device and action. When you have not tried to sign in, deny the request and open the service directly to review security activity.

Repeated unexpected prompts deserve attention even if you have not approved any. Change a compromised password from a trusted device, review active sessions and check recovery settings.

Never provide a sign-in code to someone who contacted you claiming to be support. When a support process asks for verification, independently navigate to the official support channel and read what the code actually authorizes. A message saying it approves a password reset is not merely a harmless identity check.

Test without locking every door at once

Keep one trusted session open while testing a fresh login in another browser. Confirm the new method works, then try the documented fallback. Do not remove the old method before the new one has completed enrollment and passed a real login check.

Where a service provides one-use backup codes, using one in a controlled test may invalidate that code. Mark it used or regenerate the set as the provider directs. Store the replacement set, not the superseded one.

Write down the recovery location in a private account inventory. Avoid including the secret itself in an ordinary checklist. The checklist should tell you what exists and where to find it safely.

Recheck after a device or number change

Add authentication review to the same job as setting up a new phone. Transfer or recreate credentials according to each provider's process, test them, and only then erase the old device.

For shared household needs, use service-supported family or emergency features rather than passing your one-time codes around. Our family recovery plan keeps those arrangements separate from everyday account sharing.

A good setup has two visible results: an unauthorized person cannot enter with just your password, and you still have a clear, tested route in when your normal device is unavailable.

Sources and further reading

  1. CISA: Turn on multifactor authentication Consulted 28 September 2026.
  2. Google: Available two-step verification methods Consulted 28 September 2026.
  3. FIDO Alliance: Passkeys and phishing resistance Consulted 28 September 2026.

Consult the linked documentation for current details. Settings, availability and interface labels may change.

Spotted something that needs correcting? Send a correction with this article’s title and the relevant source.