How to enable 2FA on GitHub
Enable two-factor authentication on GitHub to stop unauthorized logins. After setup, GitHub asks for a rotating code from MS Authenticator App in addition to your password.
Step-by-step setup
- 1
Locate 2FA Settings
Sign in to your GitHub account and click Settings from the drop-down menu next to your profile picture in the upper right corner.

- 2
Enable Two-Factor Authentication
Go across to Password and authentication scroll down to Two-factor authentication and then click on Enable two-factor authentication

- 3
Next Step
Select Set up using an app and click Continue.

- 4
Set up Two-Factor Authentication
In this step is shown the QR Code that contains the secret key which you need to scan with MS Authenticator App. Keep this page open as you reach for your device.Note: Do not scan the demo image shown below.

- 5
Capture QR Code
Open MS Authenticator App, tap the plus button, and hold your device up to the computer screen to scan the QR Code from GitHub web page.

- 6
Verification code
After successfully scanning the QR Code, MS Authenticator App will automatically choose the GitHub logo and autofill the account name and secret key. Click on Save when ready. Tip: You can choose the account icon by pressing on icon

- 7
Confirm OTP code
Returning to the Github, type in the six digit code from MS Authenticator App in the appropriate field. When done click Continue.

- 8
Save Your Recovery Codes
You'll now be displayed a list of recovery codes. These are used to gain access to your account in the event you lose access to your phone so you can either download them to your device, save in MS Authenticator App or store them somewhere safe. One you've done that click I have saved my recovery codes to enable two-factor authentication.

- 9
Done!
You have successfully enabled two-factor authentication(2FA) to protect your GitHub account, from now on, you will need to use the MS Authenticator App when you would like to log in to your GitHub account. GitHub recommends you test it by signing out and signing back in using two-factor authentication, so in case of problems, you can use recovery codes to access your account and correct the problem.

Menu names on GitHub can change — the official GitHub 2FA documentation ↗ always has the exact, current path.
Frequently asked questions
- Does GitHub work with authenticator apps like MS Authenticator App?
- Yes. GitHub supports TOTP authenticator apps, so you can generate its two-factor codes in MS Authenticator App.
- Is GitHub two-factor authentication free?
- Yes. Enabling authenticator-app 2FA on GitHub is free — you only need the free MS Authenticator App.
- What if I lose access to my GitHub 2FA codes?
- Use the backup or recovery codes you saved during setup. If you didn't save them, contact GitHub support to regain access, then re-add the account to MS Authenticator App.
- Should I use an authenticator app or a security key on GitHub?
- GitHub supports both. An authenticator app like MS Authenticator App is free and works on any phone; a hardware security key adds phishing resistance. You can enable both.
Generate your GitHub codes in MS Authenticator App
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Developer guides
Novaz is not affiliated with, endorsed by, or sponsored by GitHub. GitHub and its logo are trademarks of their respective owner and are used here for identification only.