Go to Security Settings under your name in the top right and enable two-factor authentication. You will be shown a QR code to scan with an authenticator app, then asked to enter a code to confirm it works.

Choose the method deliberately

Authenticator app — a six-digit code that changes every thirty seconds, generated on your device. No network needed, nothing to intercept in transit. This is the sensible default. Any reputable authenticator app will do.

Hardware security key — a physical device you touch to approve a login. The strongest option and the only one genuinely resistant to phishing: the key checks the site's real address before responding, so it will not authenticate to a lookalike domain even if you are fooled. Buy two, register both, keep one elsewhere.

SMS codes — better than nothing and worse than everything else. A texted code can be intercepted by SIM swapping, and it fails when you have no signal. Use it only if nothing else is available.

Save the backup codes properly

This is the step everyone skips and the reason most lockouts happen. When you enable two-factor you are given one-time recovery codes. They exist for the day your phone is lost, stolen, replaced or reset.

  • Not on the same device that generates your codes — a lost phone takes both.
  • In your password manager, or printed and kept somewhere physically secure. Both is better.
  • Reachable by a colleague if this is a business account and you are unavailable.

Each code works once. Generate a fresh set when they run low.

Before you replace a phone

Set up the new device, move or re-enrol every authenticator entry, confirm you can generate a working code for each account, and only then wipe the old one. Not the other way round — a factory reset destroys the secrets, and they do not always travel in a standard device backup.

If codes are always rejected

The clock on the generating device has drifted. Turn on automatic time synchronisation. This is far more common than a genuinely wrong code.

Turn it on for your email first

Email is the reset channel for everything else you own, so an attacker with your mailbox does not need any of your other passwords. Then your domain registrar, your banking, and this portal.

Was this answer helpful? 0 Users Found This Useful (2 Votes)