// PLAIN-ENGLISH HOW-TO
How to set up two-factor authentication
Two-factor authentication (2FA) is the single best thing you can do to keep your accounts safe — even if someone learns your password. Here’s how it works, and how to switch it on, in plain English.
- ● What 2FA is
- ● Best methods ranked
- ● We can set it up with you
// THE BEST METHODS, RANKED
Some 2FA is stronger than others
Any 2FA is far better than none. If you have the choice, this is the order we’d pick.
1. Passkeys
The newest and safest — your fingerprint, face or device PIN replaces the password entirely. Nothing to type, nothing to steal.
2. Authenticator app
A free app (like Microsoft or Google Authenticator) shows a 6-digit code that changes every 30 seconds. Strong and easy.
3. Hardware key
A small physical key you tap or plug in. Excellent for high-value accounts.
4. Text-message code
A code sent by SMS. Better than nothing, but can be intercepted — use a stronger method where you can.
// 5 STEPS FOR ANY ACCOUNT
Turning it on, step by step
-
01
Open your account’s security settings
Sign in, then look for ‘Security’, ‘Password & security’ or ‘Sign-in’. The wording varies slightly by service.
-
02
Find ‘two-step’ or ‘two-factor’
Look for ‘Two-step verification’, ‘2-Step Verification’ or ‘Two-factor authentication’ and choose to turn it on.
-
03
Pick your method
Choose a passkey or authenticator app if offered; otherwise a text code. Follow the prompts to link it.
-
04
Save your backup codes
You’ll be given recovery codes — print them or write them down and keep them somewhere safe. They get you back in if you lose your phone.
-
05
Add a second method
Set up a backup (a second method or a trusted device) so you’re never locked out.
Turn it on for the accounts that matter
Start with your email — it’s the master key to everything else — then your bank, then social media. Here are the official pages:
- Microsoft / Microsoft 365: account.microsoft.com/security (see also our Microsoft 365 security guide).
- Google / Gmail: myaccount.google.com/security → 2-Step Verification.
- Apple ID: Settings → your name → Sign-In & Security → Two-Factor Authentication.
- Facebook & Instagram: Settings → Accounts Centre → Password and security.
- Online banking: in your banking app or website’s security settings — most banks now build this in.
- WhatsApp: Settings → Account → Two-step verification.
For more, the UK’s National Cyber Security Centre has clear advice on setting up 2FA.
Don’t get locked out
- Save your backup/recovery codes somewhere safe.
- Add a second method or trusted device.
- When you change phones, move your authenticator app across first (see our guide to a lost or stolen phone).
Prefer a hand? We’ll set 2FA up with you over a secure remote session — patiently, and we always call before we connect.
// GOOD QUESTIONS
Frequently asked
Is text-message 2FA safe?
It’s much safer than no 2FA, but text codes can occasionally be intercepted (for example through ‘SIM-swap’ fraud — see our smishing & vishing page). Use a passkey or authenticator app where you can.
What’s a passkey?
A passkey lets you sign in with your fingerprint, face or device PIN instead of a password. There’s nothing to remember and nothing for a scammer to steal — it’s the safest option where it’s offered.
What if I lose the phone with my authenticator app?
That’s what your backup codes and second method are for. Keep recovery codes safe, and ideally add a trusted device. We can help you get back in.
Is two-factor authentication free?
Yes — it’s a free feature built into almost every major account. Authenticator apps are free too.
Rather we set it up with you?
We’ll switch on 2FA across your important accounts together — calmly, in plain English, over a secure session.
01202 775566 · help@365techies.co.uk · MON–FRI 9AM–5PM