June 9, 2026
What is two-factor authentication (2FA)? A beginner's guide
If a website has ever asked you for a code after your password, you've used two-factor authentication — usually shortened to 2FA. It's the single most effective thing most people can do to protect their online accounts.
The idea in one sentence
A password is something you know. 2FA adds a second proof — usually something you have, like your phone — so that knowing the password alone is no longer enough to log in.
Why one factor isn't enough
Passwords leak constantly: in data breaches, through phishing emails, or because they're reused across sites. Once an attacker has your password, they have your account. With 2FA switched on, they'd also need your second factor — which they don't have.
The common types of second factor
- Authenticator app — a rotating 6-digit code generated on your device. This is the sweet spot of security and convenience. See what TOTP is.
- SMS text message — a code texted to your number. Better than nothing, but weaker than an app.
- Security key or passkey — a physical key or a cryptographic credential. The strongest option; see passkeys vs authenticator apps.
How to get started
Pick your most important account first — usually your email — and turn on the "authenticator app" option. It takes about a minute: you scan a QR code, and the app starts producing codes.