August 18, 2026
7 common 2FA setup mistakes (and how to avoid them)
Two-factor authentication is one of the best security moves you can make — but a handful of avoidable mistakes trip people up. Here are the seven that matter most.
1. Not saving your backup codes
The single biggest cause of lockouts. Every service shows you backup codes when you enable 2FA. Save them before you click away — not later.
2. Storing backup codes on the same phone
If your backup codes live in a note on the phone that also holds your authenticator, losing that phone loses both. Keep them somewhere separate.
3. Screenshotting the QR code into your camera roll
The QR code contains your secret key. A screenshot sitting in your photos is a copy of your 2FA anyone with your gallery can use. Scan it, confirm a code works, then move on.
4. Choosing SMS when an app is offered
SMS codes can be stolen with a SIM swap. Pick "authenticator app" whenever it's available.
5. Protecting everything except your email
Your inbox is the master key to every other account. If it's the one thing without 2FA, the rest isn't really protected.
6. Forgetting to remove 2FA from an old phone
Selling or recycling a phone? Move your accounts to the new device first, then wipe the old one — here's how.
7. Sharing a code with "support"
No legitimate company ever asks for your 2FA code. Anyone who does is phishing.
Avoid these seven and your 2FA will be both strong and recoverable. Browse setup guides →