Updated: February 2024 • Reading time: 10 minutes

Two-factor authentication, also called two-step verification or multi-factor authentication, is the single most effective security measure available to the average user. It is simple to set up, free to use, and blocks approximately 99 percent of automated account takeover attacks. If you only make one change to improve your online security this year, enable 2FA on your most important accounts.

This guide explains the different types of 2FA, ranks them by security, walks through setup, and recommends the best authenticator apps for different needs.

How Two-Factor Authentication Works

Authentication is the process of proving you are who you claim to be. Online accounts traditionally use single-factor authentication: something you know, which is your password. The problem with passwords is that they can be stolen, guessed, or leaked without your knowledge.

Two-factor authentication adds a second factor, something you have or something you are. This second factor could be a code generated by an app on your phone, a text message sent to your phone number, a tap on a physical hardware key, or a biometric factor like your fingerprint. Even if an attacker obtains your password, they cannot access your account without also having access to your second factor.

Think of 2FA as adding a deadbolt to your front door. A password alone is like a standard lock that can be picked. Adding 2FA is like installing a deadbolt that requires a separate key. A burglar who picks the main lock still cannot open the door without the deadbolt key.

Types of Two-Factor Authentication, Ranked by Security

1. Hardware Security Keys (Highest Security)

Hardware security keys like YubiKey, Google Titan, and Thetis are physical devices, typically USB-A, USB-C, or NFC, that you plug into your computer or tap against your phone to authenticate. They use the FIDO2 and U2F standards, which provide built-in phishing protection because the key verifies the domain of the website requesting authentication before responding.

Hardware keys are the strongest form of 2FA because they are physically separate from your computer and phone, immune to remote attacks, and resistant to phishing. The main trade-off is cost, typically $25 to $55 per key, and the need to carry the key with you. For maximum security, purchase two keys: one for daily use and one stored in a safe location as a backup.

Hardware keys are supported by major services including Google, Microsoft, Facebook, Twitter, Dropbox, and GitHub. Many password managers also support hardware key authentication.

2. Authenticator Apps (High Security)

Authenticator apps generate time-based one-time passwords (TOTP) that change every 30 seconds. When you set up 2FA on a service, you scan a QR code with the authenticator app, which then generates codes unique to that service. When you log in, you enter your password and then the current code from the app.

Authenticator apps are significantly more secure than SMS-based 2FA because the codes are generated on your device and are never transmitted over phone networks. They are not vulnerable to SIM swapping attacks, and they work even without cellular service or an internet connection.

The main vulnerability of authenticator apps is that if you lose your phone and do not have backup codes or a recovery method, you could be locked out of your accounts. This is why storing backup codes securely and enabling multi-device support where available is important.

3. SMS and Phone Calls (Moderate Security, Better Than Nothing)

SMS-based 2FA sends a verification code to your phone number via text message when you attempt to log in. Phone call 2FA works similarly, with an automated call reading the code. This is the most widely supported form of 2FA and requires no additional setup beyond having a phone number.

SMS-based 2FA has known vulnerabilities. SIM swapping attacks, where an attacker convinces your mobile carrier to transfer your phone number to their SIM card, can intercept your 2FA codes. SMS messages can also be intercepted through SS7 protocol attacks, though these are more sophisticated. Despite these weaknesses, SMS-based 2FA still blocks the vast majority of attacks. The gap between having no 2FA and having SMS-based 2FA is far larger than the gap between SMS and authenticator apps.

Key Point: Use the strongest form of 2FA each service supports. If a service only offers SMS-based 2FA, enable it. SMS-based 2FA is dramatically better than no 2FA. Upgrade to an authenticator app or hardware key when those options are available.

Best Authenticator Apps Compared

If you are ready to move beyond SMS-based 2FA, these three authenticator apps are the most popular and reliable options:

Feature Authy Google Authenticator Microsoft Authenticator
Multi-Device Sync Yes, cloud-encrypted backup Yes, synced to Google Account Yes, synced to Microsoft Account
Desktop App Yes (Windows, macOS, Linux) No No
Platform Support iOS, Android, Desktop iOS, Android iOS, Android
Backup Recovery Encrypted cloud backup with password Cloud sync with Google Account Cloud sync with Microsoft Account
Account Required Yes (phone number) No (but for sync, Google Account needed) Yes (Microsoft Account)
Passwordless Login No No Yes (Microsoft accounts)
Price Free Free Free

Authy (Best Overall for Most Users)

Authy is the best choice for most people because of its multi-device support and encrypted cloud backup. If you lose your phone or upgrade to a new one, you can restore your 2FA codes by verifying your identity through Authy's recovery process. The desktop app is a convenient backup: if your phone is unavailable, you can still access your 2FA codes from your computer.

Authy requires a phone number to set up, which some privacy-conscious users may not prefer. The encrypted backup is protected by a separate backup password that you create. Without this password, even Authy cannot access your stored codes.

Google Authenticator (Simplest, Widely Supported)

Google Authenticator is the most widely used authenticator app, with a clean, straightforward interface. It previously did not support any form of backup or transfer, which meant losing your phone meant losing access to all your 2FA-protected accounts. Google has since added cloud sync to your Google Account, though this feature links your 2FA security to your Google Account security.

Google Authenticator is a solid choice if you want a simple, no-frills authenticator app and are comfortable with the trade-off of syncing codes through your Google Account. Setup is as simple as scanning QR codes, and the app requires no login or personal information to use the basic functionality.

Microsoft Authenticator (Best for Microsoft Ecosystem Users)

Microsoft Authenticator integrates tightly with Microsoft accounts, offering passwordless login as an alternative to entering both a password and a code. For Microsoft services, you can approve login requests with a single tap rather than typing a numeric code. For other services, it functions as a standard TOTP authenticator app.

If you use Microsoft 365, Outlook, or other Microsoft services regularly, Microsoft Authenticator provides a smoother experience than the alternatives. The cloud backup is tied to your Microsoft Account, which you probably already use.

How to Set Up 2FA with an Authenticator App

Setting up 2FA varies slightly between services, but the process follows a consistent pattern:

  1. Download and install an authenticator app. Choose Authy, Google Authenticator, or Microsoft Authenticator from your device's app store.
  2. Go to the security settings of the service you want to protect. Look for options labeled "Two-Factor Authentication," "Two-Step Verification," "Multi-Factor Authentication," or "Login Security."
  3. Select the authenticator app option. The service will display a QR code on your screen.
  4. Open your authenticator app and add a new account. Point your phone's camera at the QR code on your screen. The app will scan the code and start generating codes for that service.
  5. Enter the current code from the app into the service to verify setup. This confirms that the app is generating valid codes.
  6. Save the backup codes provided by the service. Every service that supports 2FA provides a set of backup codes, typically 8 to 10 single-use codes. Print these out or save them in a secure location, such as a password manager. These codes allow you to access your account if you lose your phone or cannot use your authenticator app.

Key Point: Do not skip the backup codes step. If you enable 2FA and then lose access to your authenticator app without backup codes, you may permanently lose access to your account. Store backup codes somewhere you can access without needing 2FA, such as a printed copy in a secure location.

Which Accounts Should You Protect with 2FA First?

Start with the accounts that would cause the most damage if compromised. Prioritize them in this order:

  1. Email accounts. Your email is the master key to your digital identity because it can be used to reset passwords for almost every other service. Protect your primary email account with the strongest form of 2FA available.
  2. Financial accounts. Banking, investment, payment services like PayPal, and any service that stores payment information.
  3. Password manager. If you use a password manager, its master account should have 2FA enabled. This protects every password stored in the manager.
  4. Cloud storage. Accounts that contain sensitive documents, photos, and backups.
  5. Social media. Compromised social media accounts can be used to scam your contacts and damage your reputation.
  6. Work and productivity accounts. GitHub, project management tools, and any account containing work-related data.

Common 2FA Concerns Addressed

"What if I lose my phone?"

This is the most common concern about 2FA, and the answer is backup codes and recovery methods. When you enable 2FA, the service provides backup codes for exactly this scenario. Store them securely. Authenticator apps with cloud backup like Authy also solve this problem by allowing you to restore your codes on a new device.

"Does 2FA make logging in too slow?"

The extra step adds about 10 seconds to the login process for most services. Many services now support "remember this device" options that only require the 2FA code periodically, reducing the frequency of the extra step. Passwordless options like Microsoft Authenticator's push notification approval or hardware key tap are actually faster than typing a password.

"What about services that do not support 2FA?"

Some older or smaller services still do not support any form of 2FA. For these accounts, make sure the password is unique (generated by a password manager) and monitor the account closely for suspicious activity. Contact the service and request they add 2FA support. Consumer demand drives adoption.

Start Securing Your Accounts Today

Set up 2FA on your email and financial accounts first, then work through the rest. The time investment is minimal, and the security benefit is substantial.

Explore Security Tools