Understand what changes
Multi-factor authentication adds a different kind of proof to a password. Entering a second password is not a second factor. Authenticator codes, device approvals and passkeys have different properties. Passkeys can provide phishing-resistant sign-in; ordinary one-time codes can still be stolen by a convincing fake login page.
This guide uses a personal Google account as an example. Other services use different labels. It does not require paid Microsoft Entra Conditional Access or a business security subscription.
Set it up carefully
- Open your account settings directly from the genuine service. For Google, go to Security and select 2-Step Verification. Avoid links in unexpected security emails.
- Choose an available method you can maintain. An authenticator app can be free. A hardware security key costs money unless you already have one, so it is not required here.
- Complete the enrolment challenge. Read the screen carefully before approving a prompt: it should correspond to the sign-in you just initiated.
- Add a recovery method the service supports and generate backup codes where available. Keep them private; someone with a valid code may be able to sign in.
Prove it works before signing out everywhere
Use a second browser profile or private window to attempt a genuine sign-in. Confirm the additional factor is requested and accepted. The first browser may remain signed in because it already has a valid session. That does not necessarily mean MFA failed.
Test one recovery code if the service permits it, mark it as used and store the remaining codes securely. Do not keep your only recovery material inside an account you would need those same codes to unlock.
Avoid approval fatigue
An unexpected approval request is a warning to investigate, not a reminder to tap Yes. Deny it, inspect your account's recent activity and change exposed credentials from a trustworthy device. Never tell a caller the code, even if they claim to be support.
Common problems
A wrong phone clock can break time-based codes. Check automatic date and time before repeatedly trying. When replacing a phone, enrol and test the new device before wiping the old one. SMS can be better than password-only access but has weaknesses such as SIM swapping.
Keep the recovery plan current
Review methods after a phone-number change or lost device. Remove old factors after the replacement works. MFA reduces account-takeover risk; it does not make malicious downloads or already-stolen session cookies harmless.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.