Skip to content
Digital Life Check

What is two-factor authentication (2FA)?

Two-factor authentication adds a second check when you log in, so a stolen password isn't enough. Start with your email account.

Written by
Digital Life Check editorial team
Last checked
On this page
  1. What it is
  2. Why a strong password isn't enough
  3. The types, strongest first
  4. Which accounts to protect first
  5. How to turn it on
  6. Next steps

Quick answer: two-factor authentication (2FA) means that logging in needs your password plus a second thing — usually a code on your phone, a fingerprint or face scan. A criminal who steals your password still can't get in. Turn it on for your email first, then banking, shopping and social media. And never share a login code with anyone.

What it is

Two-factor authentication goes by several names: two-step verification (2SV), multi-factor authentication (MFA) or 2FA. They all mean the same thing: a second step after your password to prove it's really you.

The National Cyber Security Centre (NCSC) calls turning it on one of the most effective ways to protect your online accounts.

Why a strong password isn't enough

Passwords can be stolen through no fault of your own. The NCSC says the most common way is a data breach at a company that holds your details. Criminals then try those stolen passwords on other sites. They also trick people into typing passwords into fake login pages. A strong password doesn't help in either case — the second step does.

You won't usually be asked for the second step every time. Most services only ask when something unusual happens, such as a login from a new device or a password change.

The types, strongest first

TypeHow it worksHow strong
Passkey or security keyYour device confirms it's you with your face, fingerprint or screen PIN, or you tap a small physical keyStrongest
Authenticator app or app promptAn app on your phone shows a code that keeps changing, or asks "Is this you?"Strong
Text message (SMS) codeA code is texted to youBetter than nothing

Passkeys

A passkey replaces your password altogether. Your device checks it's you using the same method you use to unlock it. The NCSC now recommends passkeys over passwords wherever a service offers them. It says passkeys resist phishing because they can't be intercepted, reused or stolen like passwords, and are at least as secure as the strongest password combined with 2SV.

Look for a passkey option in the account's security settings, or accept the prompt when a service offers to create one.

Security keys

A small device you buy and keep on your keyring. Apple, for example, offers them as an option on an Apple Account for people who want extra protection from targeted attacks such as phishing. Read more in what is a security key?

Authenticator apps

The NCSC describes these as the main alternative to text messages. They work without a mobile signal and you don't have to wait for a text. Google Authenticator and Microsoft Authenticator are examples the NCSC gives.

Text message codes

This is the most common kind and often the default. The NCSC says text messages are not the most secure type of 2SV but still offer a huge advantage over not using any. If SMS is all an account offers, turn it on.

Never share a login code. A real company, and a real friend, won't ask you to read out or forward a code that has been sent to you. Which? reports scammers asking people to pass on a one-time code "to join a group video call" — the code actually lets them take over the victim's WhatsApp account.

Which accounts to protect first

  1. Your email. This matters most. The NCSC explains that anyone with access to your inbox can reset the passwords on your other accounts, read private information and send messages pretending to be you.
  2. Your bank and payment accounts.
  3. Your Apple or Google account, which often holds your photos, backups and saved passwords.
  4. Online shopping accounts.
  5. Social media and WhatsApp, which scammers take over to target your friends and family.

How to turn it on

  1. Open the account's settings and look for Security, Sign-in or Login.
  2. Find Two-step verification, Two-factor authentication or Passkeys.
  3. Follow the steps. If you're offered a choice, pick a passkey or authenticator app over SMS.
  4. Save your backup codes somewhere safe. The NCSC says these are ideal if you lose your phone. Each one works once.
  5. Where you can, add a second backup method too.

If an important account like your email doesn't offer any form of 2SV, the NCSC suggests making sure it has a strong, unique password, and even considering switching to a service that does.

Next steps

Sources

Last checked: 22 September 2026

Optional · commercial links

Tools that can help

The steps above are free. If you would rather have a tool take care of it, these are the ones we link to.

  • Passwords

    What is a security key, and do you need one?

    A security key is a small physical device that proves it's you when you sign in. It's the form of two-step verification that fake websites can't fool. Here's who it's for.

    Last checked 22 September 2026

  • Passwords

    Are password managers safe?

    A password manager is much safer than reusing the same few passwords. Here's how they keep your passwords protected, where the real risks are, and how to choose one.

    Last checked 22 September 2026