Two-Factor Authentication Guide: The Methods That Matter

Even the strongest password can leak. Two-factor authentication (2FA) adds a second proof that you are you — and the method you choose matters enormously. Here is the practical ranking.

Why passwords alone are not enough

Passwords leak constantly: breaches, phishing, malware, shoulder-surfing. Two-factor authentication means a stolen password is not sufficient — the attacker also needs your second factor, which is typically something on your person. Microsoft's research has consistently found that MFA blocks the vast majority of automated account-takeover attempts.

Think of it this way: your password is "something you know." The second factor should be "something you have" (your phone, a security key) or "something you are" (a fingerprint). Two factors from different categories is what makes the combination strong.

The methods, ranked

  1. Passkeys / hardware security keys — best. Cryptographic, phishing-resistant, and increasingly built into phones and laptops. A passkey cannot be phished because it only works on the real site's domain. If a service offers passkeys, use them.
  2. Authenticator apps — excellent. Apps like Google Authenticator, Authy, or your password manager's built-in TOTP generate rotating six-digit codes. Immune to SIM-swap attacks, works offline.
  3. SMS codes — better than nothing. Convenient but vulnerable to SIM swapping and interception. Use SMS only when no stronger option exists, and never for your email or password manager if alternatives are offered.
  4. Email codes — weakest common option. If your email is compromised, every "verify via email" second factor falls with it. Fine as a backup, poor as a primary.

Setting up 2FA without lockouts

Priority order: email first, then password manager, then banking and money apps, then social media. Email is the recovery path for almost everything else, so it gets protected first.

When enabling TOTP on a site, you will see a QR code. Scan it with your authenticator app — and save the setup key/QR screenshot in your password manager too. That way, a lost phone does not mean lost accounts; you can re-add the code generator on a new device.

Recovery codes: the part everyone skips

Most sites show one-time recovery codes when you enable 2FA. These bypass the second factor entirely — which makes them both your lifeline and a target. Store them in your password manager (or printed and locked away), never in plain notes or screenshots on your camera roll. Test one recovery path per critical account so you know it works before you need it.

When 2FA codes do not work

Authenticator codes failing is almost always clock drift. TOTP codes are time-based: your phone and the server must agree on the time within about 30 seconds. If codes are rejected, check that your phone uses automatic date and time (not manual), then generate a fresh code — each lasts only 30 seconds, and entering an expired one is the most common failure of all.

Other culprits: scanning the QR code twice creates two entries and you may be reading the stale one — delete duplicates. If you switched phones, codes do not transfer unless your authenticator app syncs or you saved the setup keys. And if a site offers "remember this device," use it on personal hardware to reduce how often you need codes at all.

Locked out completely? This is what recovery codes are for — the one-time codes shown when you enabled 2FA. Enter one instead of the authenticator code, then immediately re-enroll 2FA and store the new recovery codes in your password manager. If you skipped saving them, account recovery goes through the site's support process, which is deliberately slow — another reason email (the recovery hub for everything) deserves 2FA first.

2FA pairs naturally with unique strong passwords: the password keeps casual attackers out, and the second factor stops the professionals. If you take one action after reading this, enable an authenticator app on your email account today.

Frequently asked questions

A login that requires two proofs: something you know (your password) plus something you have (your phone or a security key). A stolen password alone is no longer enough.
It is better than nothing but the weakest common method — attackers can hijack phone numbers via SIM swapping. Use an authenticator app or passkey whenever offered.
Passkeys are cryptographic login credentials stored on your device that cannot be phished. If a service offers them, they are the strongest and most convenient option available.
Use the recovery codes the site gave you when you enabled 2FA, or restore from the setup keys you saved in your password manager. This is why saving recovery codes matters.