Why Text-Message Codes Aren’t Enough Anymore
A login code by text (SMS) still stops the vast majority of automated attacks — so if a service only offers SMS, turn it on without hesitation. But text messages were never built for security. In SIM-swapping attacks, criminals sweet-talk your phone carrier into moving your number to their SIM card — and from that moment, your “secure” codes go straight to them. SMS codes can also be grabbed on insecure networks.
Authenticator apps fix this by generating codes on your device — nothing travels over the phone network, so there’s nothing to intercept. And the newest option, passkeys (Face ID or fingerprint sign-in), drops codes entirely and can’t be phished at all. So the pecking order goes like this: passkeys beat authenticator apps, authenticator apps beat SMS, and SMS beats nothing by a mile. This guide gets you set up with authenticator apps — the best option that’s widely available today.
The 5-Minute Setup: Install an Authenticator App First
Do this once, then reuse the same app for every account below. And a confession up front: the first time I set one of these up, I skipped saving the backup codes and paid for it when I switched phones. You’ll see the warning about that below — it’s there because of people like me.
- Install a free authenticator app. Solid picks: Google Authenticator, Microsoft Authenticator, Authy, or 1Password — all free on iPhone and Android. Authy has one nice extra: optional encrypted multi-device sync, so your codes survive a lost phone.
- Open the app and run through its quick setup — usually just confirming you’re ready to add accounts. Don’t add anything manually yet; each account below will hand you a QR code to scan.
- Put the app somewhere you’ll actually find it — your home screen, not buried three folders deep. You’ll open it rarely, but when you need a code, you need it fast.
Turn It On: Google Account
- Head to myaccount.google.com and click Security in the left sidebar.
- Under “How you sign in to Google,” click 2-Step Verification, then Get started (you’ll sign in once more to prove it’s you).
- Google may nudge you toward phone prompts first — look for the “Authenticator app” option under “Add more second steps” and choose it.
- A QR code appears. Open your authenticator app, tap the +, choose Scan QR code, and point your camera at it.
- Type in the 6-digit code the app now shows, click Verify, then Turn on. Done — and save the backup codes Google shows you (more on those below).
Turn It On: Apple Account
- On your iPhone, go to Settings > [your name] > Sign-In & Security.
- Tap Two-Factor Authentication. Heads-up: Apple IDs created in recent years already have this on — if yours does, you’re done with this step.
- If it’s off, tap Continue and verify a trusted phone number. Apple sends codes as push alerts to your trusted devices (iPhone, iPad, Mac) instead of through an authenticator app — approve the alert showing the login location on a device you’re already signed into.
- On a Mac, the same setting lives under System Settings > [your name] > Sign-In & Security. While you’re there, glance at your trusted devices list and remove any old devices you no longer own.
Turn It On: Microsoft Account
- Go to account.microsoft.com, sign in, and open Security > Advanced security options (it says “More security options” on some layouts).
- Under “Ways to prove who you are,” click “Add a new way to sign in or verify.”
- Choose “Use an app.” If you installed Microsoft Authenticator, pick it for push-approve sign-ins; otherwise take the generic authenticator-app option, which works fine with Google Authenticator or Authy.
- Scan the QR code with your authenticator app, enter the test code, and confirm. Microsoft will also offer passwordless sign-in through the app — worth switching on, since it replaces the password entirely.
Turn It On: Facebook and Instagram
- In the Facebook app or site, go to Settings > Accounts Center > Password and security > Two-factor authentication.
- Pick your profile, choose “Use authentication app,” and scan the QR code with your authenticator app.
- Enter the code to confirm, and store the recovery codes it shows you. Instagram runs on the same Accounts Center, so one setup covers both.
Two-Factor Authentication FAQs
What happens if I lose my phone?
Sign in with your saved backup codes, then set up the authenticator on the new phone. If you use Authy with multi-device sync switched on, your codes just transfer over. Worst case, every major service has an account-recovery process — slower, but it gets you back in.
Is SMS two-factor still worth using?
Yes. It blocks nearly all automated credential-stuffing attacks, and those are by far the most common kind. SIM-swapping is real, but it targets specific high-value victims. Turn on SMS 2FA anywhere that doesn’t offer an app option — then upgrade to app-based wherever you can.
What’s the difference between 2FA and passkeys?
Passkeys replace the password completely — you sign in with Face ID, a fingerprint, or a device PIN, and there’s no code for a phisher to steal. Google, Apple, and Microsoft all support them now. When a service offers “create a passkey,” say yes. It’s stronger than any 2FA code.
Will 2FA annoy me every single day?
Barely. Trusted devices stay signed in — you’ll usually only punch in a code on a brand-new device, a new browser, or roughly once every 30 days. Day to day, it feels like nothing changed.
Which accounts should I protect first?
In this order: your primary email (the master key to every password reset), your Apple/Google/Microsoft accounts, banks and payment apps, then social media. Email first. Always. Whoever controls your email can reset everything else.