Setting up two-factor authentication on your accounts

A step-by-step guide for individuals on what two-factor authentication is, why it matters and how to enable it on your most important online accounts to significantly reduce the risk of unauthorised access.

1. What is two-factor authentication?

Two-factor authentication (2FA), sometimes called two-step verification or multi-factor authentication (MFA), adds an extra layer of security to your online accounts. Instead of relying solely on a password to prove your identity, 2FA requires a second piece of evidence — something you have (such as your phone) or something you are (such as a fingerprint).

This means that even if a criminal obtains your password — through a data breach, phishing attack or malware — they cannot access your account without also having your second factor.

SUVAT recommends that all individuals enable two-factor authentication on their email, banking, social media and cloud storage accounts as a priority. Your email account is particularly important, as it is often used to reset passwords on other services.

2. Types of two-factor authentication

There are several types of 2FA, each offering different levels of convenience and security:

Type How it works Security level
SMS codes A one-time code is sent to your mobile phone by text message each time you log in. Good — better than no 2FA, but vulnerable to SIM-swapping attacks where criminals port your phone number to their device.
Authenticator apps An app on your phone (such as Google Authenticator, Microsoft Authenticator or Authy) generates a time-based one-time code that changes every 30 seconds. Very good — codes are generated locally on your device and cannot be intercepted in transit.
Hardware security keys A small physical device (such as a YubiKey) that you plug into your computer or tap against your phone. Uses the FIDO2/WebAuthn standard. Excellent — the strongest form of 2FA. Resistant to phishing because the key verifies the website's identity before responding.
Push notifications A notification is sent to an app on your phone asking you to approve or deny the login attempt. Very good — but be cautious of "MFA fatigue" attacks where criminals repeatedly send notifications hoping you will approve one by mistake.

3. How to set up 2FA on common services

3.1 Google accounts (Gmail)

  1. Go to myaccount.google.com and sign in.
  2. Select Security from the left-hand menu.
  3. Under "How you sign in to Google", select 2-Step Verification.
  4. Click Get started and follow the prompts.
  5. You can choose to receive codes via text message, use the Google Authenticator app, or add a hardware security key.

3.2 Microsoft accounts (Outlook, Hotmail)

  1. Go to account.microsoft.com and sign in.
  2. Select Security, then Advanced security options.
  3. Under "Additional security", turn on Two-step verification.
  4. Follow the prompts to set up the Microsoft Authenticator app or another method.

3.3 Apple ID

  1. On an iPhone or iPad, go to Settings > [your name] > Sign-In & Security.
  2. Tap Turn On Two-Factor Authentication.
  3. Enter the phone number where you would like to receive verification codes.
  4. Complete the verification process.

3.4 Social media accounts

Most social media platforms offer 2FA in their security settings. Navigate to your account settings, look for "Security" or "Login security", and enable two-factor authentication. SUVAT recommends using an authenticator app rather than SMS where the option is available.

3.5 Banking

Most UK banks now require some form of two-factor authentication for online banking by default, in compliance with Strong Customer Authentication (SCA) regulations. If you are unsure whether your bank has 2FA enabled, contact them directly or check their security settings in the mobile app or online banking portal.

4. Backup codes

When you enable 2FA, most services will provide a set of backup codes (also called recovery codes). These are one-time codes that you can use to access your account if you lose your phone or cannot receive your second factor.

4.1 How to store backup codes safely

  • Write them down and store them in a secure physical location, such as a safe or locked drawer.
  • Store them in a password manager if you use one.
  • Do not store them in an unencrypted file on your computer or phone, and do not take a screenshot that syncs to cloud photo storage.
  • If you use your backup codes, generate new ones immediately — each code can typically only be used once.
What if I lose my phone? If you lose your phone and have not saved your backup codes, you may be locked out of your accounts. This is why it is essential to save backup codes when you first set up 2FA. Some services also allow you to register multiple devices or phone numbers as a fallback.

5. Why two-factor authentication matters

Passwords alone are no longer sufficient to protect online accounts. Data breaches expose billions of credentials each year, and many people reuse passwords across multiple services. Criminals use automated tools to test stolen credentials against thousands of websites simultaneously — a technique known as credential stuffing.

Two-factor authentication dramatically reduces the risk of account compromise. According to industry research, accounts with 2FA enabled are over 99% less likely to be successfully attacked through credential-based methods.

5.1 Accounts to prioritise

If you do not enable 2FA on every account, prioritise the following:

  1. Email — your email account is the gateway to all your other accounts, as it is used for password resets.
  2. Banking and financial services — direct access to your money.
  3. Cloud storage — may contain personal documents, photographs and sensitive information.
  4. Social media — compromised social media accounts are used to defraud your contacts.
  5. Work accounts — a compromised work account can affect your employer and colleagues.

6. Further reading