How to enable 2FA and not lose access to your account

Start by mailing. Select the method, add it to your account and prepare a spare for the day your phone stops working.

3 min readFor execution: 10–15 minutes to the first account
In this guide

Someone knows your password. Without additional protection, they can try to log in exactly as you do. With the 2FA on, they still have to pass a second check — for example, give the code from the application or use the security key.

It is best to start with an e-mail box, because it is where the links to change passwords in other services come in. Prepare running account access, phone and recovery code space. Leave the current session logged in until you check out the new method.

Which method to choose?

If the service supports passkey or FIDO2 key, consider this option first. If it only offers an application with codes and SMS, the app will not depend on your phone number.

Method How it works and what it gives
Passkey / FIDO2 key You unlock the device or use a key. Confirmation is related to the right site, which protects against typical fraud of data on a fake page.
TOTP app You prescribe a changing code. It works without network coverage, but the code can be extorted and used immediately.
SMS Better than the password itself, but it depends on the number and operator security.

Passkey can replace entering a password and code. So don’t be surprised if after its use the service does not ask for an additional six digits. The mode of logging depends on the service.

Configuration of the application with codes

The names of the settings vary from service to service. Search for the section “Safety”, “Login” or “Two-stage verification”. The following procedure applies to TOTP applications, not to approve push notifications.

  1. Open the settings on your account. Enter through the app or a known address. Select the addition of the authentication application. The service can ask for the password again.
  2. Add an entry in the application. Scan the QR code displayed in the settings. If you do everything on one phone, use the option to manually enter the key as long as the service provides it.
  3. Give the entry a recognizable name. "Post – private account" helps more than another anonymous Google entry. This is important when you serve several accounts in the same service.
  4. Enter the generated code in the service and confirm the configuration. The QR scan itself does not mean that 2FA is already on. Seek confirmation in the account settings.

The QR code of the configuration contains a secret to generate more codes. Do not put it in the application for technical assistance. If someone has seen it, reconfig the application using a new secret.

Prepare the emergency entrance.

Recovery codes are a separate thing: they allow you to enter your account when the normal 2FA method is not available. If the service offers them, save them now. You can keep the printout secure or the encrypted copy you enter without this phone.

Ask yourself one practical question: “The phone doesn’t work. Where do I get the code?” If the answer is “from the app on this phone”, the plan has a gap. For the password manager alone, the recovery copy cannot exist only inside the locked safe.

Do not assume that each service releases backup codes. An alternative may be a second registered key or another official recovery method.

Check one full login

Open your private browser window and log in from the beginning. Use just added method. Leave the previous window open in case of a problem. Success is entering the right account, not just the appearance of the code in the application.

If the code does not match, check the account name and automatically set the time on your phone. Wait for a new code and try again. Do not delete the working method during diagnosis.

Is 2FA enough to keep your account safe?

It does not give you full protection. You still need a unique password, current device and caution when logging in. Entering your password and TOTP code on a fake page can enable the cheater to log in in in real time.

Do not approve a login notification that has not been started at your initiative. After you have configured your first account, go to the password manager and other important services. You don’t have to do the whole list of one day.