What is two-factor authentication, and how does it work?
Understand 2FA, authentication apps, text-message codes, passkeys, security keys, backup codes, and safer account recovery.
Two steps are strongest when they use different factors
A password and a security code are two steps, but the security benefit comes from making an attacker defeat more than one type of proof. Common factor categories are knowledge, possession, and inherence.
- Something you know: password or PIN
- Something you have: phone, authenticator, passkey, or security key
- Something you are: fingerprint, face, or another biometric
Common 2FA methods
Text-message codes are widely available and better than relying on a password alone, but phone-number attacks and convincing phishing pages can still defeat them. Authentication apps generate codes without depending on a text message, while hardware security keys and properly implemented passkeys can provide stronger resistance to phishing.
Use the strongest method the service supports and that you can recover safely. A strong option that locks you out permanently is not a complete plan.
Save recovery options before you need them
When enabling 2FA, download or print the backup codes and store them somewhere secure and separate from the everyday device. Add a second trusted authentication method when the service allows it.
Never give a login code to someone who calls or messages you. A legitimate support representative should not need the one-time code that approves access to your account.
What to do when a login request appears unexpectedly
Deny an approval request you did not initiate. Then open the service through its official app or a saved address, review recent activity, change a compromised password, and remove unfamiliar devices or recovery methods.
Repeated unexpected prompts can mean someone already knows the password. Do not approve a notification simply to make the alerts stop.
Frequently asked questions
Is 2FA completely secure?
No security method is absolute, but 2FA makes many common account takeovers substantially harder.
Is an authentication app better than text messages?
It avoids some phone-number attacks, while security keys and passkeys can offer stronger phishing resistance when supported.
What happens if I lose my phone?
Use a saved backup code, secondary authenticator, security key, or the service’s verified recovery process.
Sources
Primary and official references used for this guide:
Published August 3, 2026 · Reviewed for clarity and source accuracy.