Blog/Account security

What Is Two-Step Verification and Why Use It?

Two-step verification, also called 2FA or MFA, adds a second check when you sign in. What it is, why it stops most account takeovers, the main methods, and where to turn it on first.

CyberWatch AI29 September 2026 · 2 min read
A hand holding a phone showing a passcode screen

Passwords get stolen, guessed, leaked and phished. Two-step verification (also called two-factor authentication, 2FA, or multi-factor authentication, MFA) means that a stolen password on its own is no longer enough to get into your account. It is one of the most effective things you can do to protect yourself online, and it takes a few minutes to set up.

How it works

When you sign in, you prove who you are in two ways:

  1. Something you know: your password.
  2. Something you have or are: your phone, a security key, or your fingerprint or face.

A criminal in another country who has your password does not have your phone. So when they try to sign in, they get stuck at step two.

The main methods, from weakest to strongest

MethodHow it worksStrength
Text message codeA code sent by SMSBetter than nothing, but vulnerable to SIM swap and phishing. See SMS code weaknesses.
Authenticator appA code generated on your phoneGood. Not affected by SIM swap. See authenticator apps.
Push approvalTap "Yes, it's me" on your phoneGood, if you never approve prompts you did not start.
PasskeyYour device confirms it is you with your fingerprint, face or PINVery strong, and resistant to phishing. See what is a passkey.
Security keyA small physical key you plug in or tapVery strong, and resistant to phishing.

The US Cybersecurity and Infrastructure Security Agency (CISA) recommends phishing-resistant methods where possible, but says any form of MFA is better than none.

Where to turn it on first

  1. Your main email account.
  2. Banking, payment and mobile money apps (many have it on by default).
  3. Your mobile network account.
  4. WhatsApp and main social media accounts.
  5. Your password manager.
  6. Your phone's cloud or app store account.

The one rule that keeps it working

Never share a code, and never approve a sign-in you did not start. Scammers who have your password will try to trick you into giving them the second step. See unexpected login prompts.

Plan for losing your phone

Before you need it, save backup codes or add a second method, so you are not locked out if your phone is lost or replaced. See backup codes and losing your phone with your authenticator on it.

Received a code you did not ask for? Someone may have your password. Do not share it, and change your password. If a message asks you for a code, paste it into CyberWatch AI Scan for a free check.

Two-step verification is one of the key steps in how to protect your accounts.

Frequently asked questions

Is two-step verification the same as 2FA and MFA?

Broadly, yes. Two-step verification, two-factor authentication (2FA) and multi-factor authentication (MFA) all mean needing something in addition to your password to sign in.

Which accounts should I protect first?

Your main email, then banking and mobile money, your mobile network account, your main social media, your password manager and your cloud or app store account.

Can two-step verification be bypassed?

Some methods can be, especially if you are tricked into sharing a code or approving a prompt. Phishing-resistant methods like passkeys and security keys are the strongest.

Sources

  1. Multifactor Authentication, US Cybersecurity and Infrastructure Security Agency
  2. Use Two-Factor Authentication To Protect Your Accounts, US Federal Trade Commission
  3. Activate 2-step verification on your email, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.