What Is Multi-Factor Authentication?
A password is important, but a password by itself may not be enough to protect an important account.
Multi-factor authentication — commonly called MFA — adds another step when you sign in. You may also see it called two-factor authentication (2FA) or two-step verification.
Instead of relying only on something you know, such as your password, your account asks for another way to verify that you are really you.
Depending on the service, that second step might be:
• An approval notification sent to your phone
• A code generated by an authenticator app
• A text-message verification code
• A passkey
• A physical security key
• Another verification method supported by the service
This extra protection is important because even if someone learns or steals your password, they may still be unable to sign in without the additional verification.
Important: Never give another person your MFA verification code, approval prompt, backup code, or account-recovery code. A legitimate support representative should not need you to give them a code so they can sign in as you.
Step 1 — Turn On MFA for Your Microsoft Account
If you use Outlook.com, Hotmail, OneDrive, Xbox, Microsoft 365 Personal, or another personal Microsoft service, your Microsoft account can use two-step verification.
1. Open your Microsoft account security settings
Go to the Microsoft Account Security page:
Sign in with the Microsoft account you want to protect.
2. Open your sign-in security settings
Select Manage how I sign in.
This page shows the methods Microsoft can use to verify that it is really you.
3. Turn on two-step verification
Find Two-step verification under the additional security options and select Turn on.
Follow Microsoft’s instructions on the screen to complete the setup.
4. Consider using Microsoft Authenticator
Microsoft Authenticator can be used to approve sign-ins or generate verification codes.
From Manage how I sign in, select Add a new way to sign in or verify, and choose the authenticator app option.
If Microsoft displays a QR code, open Microsoft Authenticator on your phone and follow the instructions to scan the code and connect your account.
5. Add backup sign-in or recovery methods
Before you finish, make sure you have more than one way to verify your identity when possible.
This is important if your phone is lost, replaced, damaged, or unavailable. Microsoft warns that losing access to your verification methods can make account recovery difficult.
Important: Never approve a Microsoft Authenticator notification you did not initiate. If you receive an unexpected sign-in approval request, deny it and review your account security.
Step 2 — Turn On MFA for Your Google Account
If you use Gmail, Google Drive, YouTube, Google Photos, or another Google service, protecting your Google Account helps protect all of those services.
1. Open your Google Account
Go to:
Sign in with the Google Account you want to protect.
2. Open Security & sign-in
Select Security & sign-in.
Under How you sign in to Google, find 2-Step Verification.
3. Turn on 2-Step Verification
Select Turn on 2-Step Verification and follow the instructions on the screen.
Google will help you choose an available verification method for your account.
4. Choose your verification methods
Depending on your account and devices, Google may offer several options, including:
• Google prompts sent to a trusted device
• Google Authenticator or another authenticator app
• A passkey
• A physical security key
• A text-message or voice-call verification code
Google recommends using Google prompts instead of text-message codes when you are not using a passkey. Passkeys and physical security keys can provide even stronger protection against phishing.
5. Set up backup options
Make sure you have another way to access your account if your primary phone is lost, stolen, damaged, or replaced.
Google provides backup options that may include another trusted phone, backup codes, a security key, or a passkey on another device.
If you create backup codes, store them somewhere secure. Do not keep them somewhere that another person can easily access.
Important: Never give anyone a Google verification code or backup code. Google warns that scammers may try to use these codes to take over your account. If you receive a Google sign-in prompt that you did not initiate, select No or otherwise deny the request.
Step 3 — Turn On MFA for Your Apple Account
If you use an iPhone, iPad, Mac, iCloud, Apple Music, or other Apple services, your Apple Account protects access to important personal information, photos, messages, backups, and other Apple services.
Apple calls its MFA protection two-factor authentication. Most Apple Accounts already have it turned on.
1. Open your Apple Account security settings
On your iPhone or iPad, open Settings.
Tap your name at the top of the screen.
Select Sign-In & Security.
2. Check Two-Factor Authentication
Select Two-Factor Authentication.
If two-factor authentication is already enabled, you do not need to turn it on again.
If it is not enabled, follow Apple’s instructions on the screen to turn it on.
3. Verify your trusted phone number
Apple requires at least one trusted phone number that can receive verification codes.
Check that the trusted phone number listed on your account is still a number you can access.
When possible, consider adding an additional trusted phone number. This can help if your primary phone is lost, stolen, damaged, or unavailable.
4. Understand trusted devices
An iPhone, iPad, Apple Watch, Apple Vision Pro, or Mac that you have already signed in to using two-factor authentication can become a trusted device.
When you sign in to your Apple Account on a new device or browser, Apple may display a six-digit verification code on one of your trusted devices or send a code to a trusted phone number.
5. Consider setting up account recovery
Apple also allows you to designate an Account Recovery Contact — someone you know and trust who can help you regain access to your account if you forget your password or device passcode.
A recovery contact does not receive access to your account or personal information. They can provide a recovery code when you need help regaining access.
Important: Never give an unexpected caller, text sender, email sender, or website your Apple verification code, device passcode, password, or recovery code. If you receive a sign-in request you did not initiate, do not approve it and review your Apple Account security.
Which MFA Method Should You Choose?
Not all MFA methods provide the same level of protection, but using MFA is generally better than protecting an account with only a password.
When an account gives you several choices, consider them in roughly this order:
Passkey or physical security key
These can provide strong protection against phishing because they are designed to work with the legitimate website or service. They are an excellent option for important accounts when supported.
Authenticator app or trusted-device approval
Authenticator apps and approval prompts are convenient and generally provide stronger protection than receiving verification codes by text message.
Text-message or voice-call codes
SMS or phone verification can still add useful protection when stronger methods are not available. However, phone-based codes can be more vulnerable to attacks such as SIM swapping or someone tricking you into revealing the code.
The most important rule: use MFA
Don’t avoid MFA just because your account doesn’t offer your preferred method. If text-message verification is the only additional security option available, it is generally better to enable it than to rely on a password alone.
What If You Lose or Replace Your Phone?
Before replacing, resetting, or trading in your phone, check the MFA settings for your important accounts.
Make sure you have another way to get back into those accounts. Depending on the service, this might include:
• A second trusted device
• A backup phone number
• Backup or recovery codes stored securely
• A passkey on another device
• A physical security key
• An account recovery contact or other recovery method
If you use an authenticator app, make sure you understand how that app handles transferring or restoring your accounts before erasing your old phone.
Do not store your only recovery method on the device you might lose.
For example, if your only copy of your backup codes is a screenshot stored on the same phone used for MFA, those codes may not help you if the phone is lost or damaged.
Quick MFA Safety Checklist
Before you consider your accounts protected, take a few minutes to check the following:
• Turn on MFA for your most important accounts
• Use a passkey, security key, authenticator app, or trusted-device approval when available
• Keep at least one backup or recovery method available
• Store backup codes somewhere secure
• Review trusted phone numbers and devices periodically
• Remove old devices or phone numbers you no longer control
• Never share verification, backup, or recovery codes with anyone
• Never approve a sign-in request you did not initiate
Start With Your Most Important Accounts
You do not have to secure every account in one day.
Start with the accounts that could cause the most damage if someone gained access to them. Your primary email account is especially important because it is often used to reset passwords for your other accounts.
Good accounts to protect first include:
• Your primary email account
• Your Apple, Google, or Microsoft account
• Banking and financial accounts
• Social media accounts
• Cloud storage accounts
• Shopping accounts that store payment information
Then continue enabling MFA on other accounts that support it.
Official MFA Resources
Security menus and features can change over time. For the latest instructions, use the official guidance from each provider:
Microsoft — Two-step verification
Apple — Two-factor authentication
Remember
MFA does not make an account impossible to compromise, but it adds an important layer of protection beyond your password.
A strong password plus MFA, secure recovery options, and careful attention to unexpected sign-in requests can make it much harder for someone else to take over your account.
Digital Family Shield Tip
If an unexpected caller, email, text message, or website asks for a verification code, backup code, recovery code, password, or device passcode, stop. Do not provide it.
Go directly to the company’s official app or website and review your account from there.
Digital Family Shield provides general privacy and online-safety information. This guide is educational and does not guarantee that an account cannot be compromised.