What is two-factor authentication (2FA)?
Two-factor authentication adds a second check when you log in, so a stolen password isn't enough. Start with your email account.
- Written by
- Digital Life Check editorial team
- Reviewed by
- Not yet independently reviewed
- Last checked
On this page
Quick answer: two-factor authentication (2FA) means that logging in needs your password plus a second thing — usually a code on your phone, a fingerprint or face scan. A criminal who steals your password still can't get in. Turn it on for your email first, then banking, shopping and social media. And never share a login code with anyone.
What it is
Two-factor authentication goes by several names: two-step verification (2SV), multi-factor authentication (MFA) or 2FA. They all mean the same thing: a second step after your password to prove it's really you.
The National Cyber Security Centre (NCSC) calls turning it on one of the most effective ways to protect your online accounts.
Why a strong password isn't enough
Passwords can be stolen through no fault of your own. The NCSC says the most common way is a data breach at a company that holds your details. Criminals then try those stolen passwords on other sites. They also trick people into typing passwords into fake login pages. A strong password doesn't help in either case — the second step does.
You won't usually be asked for the second step every time. Most services only ask when something unusual happens, such as a login from a new device or a password change.
The types, strongest first
| Type | How it works | How strong |
|---|---|---|
| Passkey or security key | Your device confirms it's you with your face, fingerprint or screen PIN, or you tap a small physical key | Strongest |
| Authenticator app or app prompt | An app on your phone shows a code that keeps changing, or asks "Is this you?" | Strong |
| Text message (SMS) code | A code is texted to you | Better than nothing |
Passkeys
A passkey replaces your password altogether. Your device checks it's you using the same method you use to unlock it. The NCSC now recommends passkeys over passwords wherever a service offers them. It says passkeys resist phishing because they can't be intercepted, reused or stolen like passwords, and are at least as secure as the strongest password combined with 2SV.
Look for a passkey option in the account's security settings, or accept the prompt when a service offers to create one.
Security keys
A small device you buy and keep on your keyring. Apple, for example, offers them as an option on an Apple Account for people who want extra protection from targeted attacks such as phishing. Read more in what is a security key?
Authenticator apps
The NCSC describes these as the main alternative to text messages. They work without a mobile signal and you don't have to wait for a text. Google Authenticator and Microsoft Authenticator are examples the NCSC gives.
Text message codes
This is the most common kind and often the default. The NCSC says text messages are not the most secure type of 2SV but still offer a huge advantage over not using any. If SMS is all an account offers, turn it on.
Never share a login code. A real company, and a real friend, won't ask you to read out or forward a code that has been sent to you. Which? reports scammers asking people to pass on a one-time code "to join a group video call" — the code actually lets them take over the victim's WhatsApp account.
Which accounts to protect first
- Your email. This matters most. The NCSC explains that anyone with access to your inbox can reset the passwords on your other accounts, read private information and send messages pretending to be you.
- Your bank and payment accounts.
- Your Apple or Google account, which often holds your photos, backups and saved passwords.
- Online shopping accounts.
- Social media and WhatsApp, which scammers take over to target your friends and family.
How to turn it on
- Open the account's settings and look for Security, Sign-in or Login.
- Find Two-step verification, Two-factor authentication or Passkeys.
- Follow the steps. If you're offered a choice, pick a passkey or authenticator app over SMS.
- Save your backup codes somewhere safe. The NCSC says these are ideal if you lose your phone. Each one works once.
- Where you can, add a second backup method too.
If an important account like your email doesn't offer any form of 2SV, the NCSC suggests making sure it has a strong, unique password, and even considering switching to a service that does.
Next steps
- Make sure the password behind your 2FA is a good one: how to create a strong password, or test it with our on-device Password Check.
- Setting this up for a parent? See how to protect elderly parents from online scams.
- See how your overall setup scores with the Digital Life Score.
Sources
- Turn on 2-step verification (2SV) — National Cyber Security Centre (opens in a new tab)
- Setting up 2-Step Verification (2SV) — National Cyber Security Centre (opens in a new tab)
- Use a strong and separate password for your email — National Cyber Security Centre (opens in a new tab)
- Passkeys: what you need to know — National Cyber Security Centre (opens in a new tab)
- NCSC: Leave passwords in the past - passkeys are the future — National Cyber Security Centre (opens in a new tab)
- If you think your Apple Account has been compromised — Apple Support (opens in a new tab)
- How to spot a WhatsApp scam — Which? (opens in a new tab)
Last checked: 22 September 2026
Optional · commercial links
Tools that can help
The steps above are free. If you would rather have a tool take care of it, these are the ones we link to.