Clear, practical technology insights
Secure Your AccountsLesson 3 of 15

Enable multi-factor authentication

Multi-factor authentication adds another proof of identity after the password, but not every method resists the same attacks. A security key or passkey can bind authentication to the legitimate service, while a code typed by hand can still be relayed through a fake sign-in page. This lesson uses a platform-neutral setup sequence, prioritizes phishing-resistant methods, and treats recovery preparation as part of the setup rather than an afterthought.

14 min Beginner Secure Your AccountsReviewed 2026-07-30 00:00:00
Learning objectives

What you will learn

  • Explain what MFA adds and what it does not prevent.
  • Choose among passkeys, security keys, authenticator apps and SMS.
  • Register MFA only from an official account page.
  • Store and test recovery methods without invalidating the active session.
Before you start

What you need

  • The account password and access to its official security settings.
  • A second device, passkey-capable device, authenticator app or security key.

Compare authentication methods honestly

CISA recommends phishing-resistant MFA where possible and ranks security keys above authenticator codes and text or email codes for common deployments.

NIST explains that manually entered one-time codes are not phishing-resistant because an impostor site can relay them. Cryptographic authenticators such as FIDO-based passkeys can bind authentication to the verifier.

Any MFA is generally better than password-only access, but an unexpected prompt is evidence of a possible attack. Never approve a request merely to make repeated notifications stop.

Authentication hierarchy showing password, security key or passkey, authenticator and recovery method.
Choose the strongest method the service supports and preserve a separate recovery path.

Choose the strongest practical option

Use a passkey or FIDO security key for high-value accounts when the service supports it and you can register a backup. Authenticator number matching is preferable to a simple approve/deny push. Time-based codes are broadly available but must not be typed into sites reached through suspicious links. SMS remains useful when stronger methods are unavailable, but the mobile account and carrier PIN also need protection.

  1. 1

    List the factors offered by the service.

  2. 2

    Prefer passkey or security key with a backup key or trusted device.

  3. 3

    Otherwise choose number matching or an authenticator code.

  4. 4

    Use SMS only when stronger methods are unavailable.

  5. 5

    Avoid email as the sole second factor when the same mailbox controls account recovery.

Enable MFA from the official service

Menu names vary, but the safe sequence is stable. Begin from the official application, a saved bookmark or an address you type yourself. Do not scan a QR code from an unsolicited message or support chat.

  1. 1

    Open Account, Security or Sign-in settings.

  2. 2

    Confirm the password if requested.

  3. 3

    Choose MFA, two-step verification, passkeys or security keys.

  4. 4

    Register the primary factor and complete its verification.

  5. 5

    Generate and save recovery codes before leaving the page.

  6. 6

    Add a backup factor stored separately from the primary device.

  7. 7

    Review trusted devices and active sessions.

Test the new factor without locking yourself out

Keep the original signed-in window open while you test a separate private window or second browser. This leaves a safe route back to settings if the new factor fails. If the service generates replacement recovery codes, securely destroy the old set because it may no longer work.

  1. 1

    Start a new sign-in in a private window.

  2. 2

    Confirm the correct factor prompt appears.

  3. 3

    Reject any unrelated prompt that arrives during the test.

  4. 4

    Test a backup factor if the service allows it safely.

  5. 5

    Confirm recovery codes are stored outside the primary phone.

Verification checklist
  • New logins require the expected factor.
  • At least one backup method exists.
  • Recovery materials are accessible if the primary device is lost.
  • You know how to report an unexpected prompt.
Hands-on practice

Protect one high-value account

Start with primary email, financial services, password manager or cloud storage.

  1. 1

    Navigate to the official security page.

  2. 2

    Choose the strongest supported factor.

  3. 3

    Register and verify it.

  4. 4

    Store recovery codes separately.

  5. 5

    Test a second-browser sign-in.

  6. 6

    Review sessions and remove any device you no longer use.

Common mistakes to avoid

  • Approving an MFA prompt you did not initiate.
  • Saving recovery codes only on the authenticator phone.
  • Scanning a QR code after following an unexpected link.
  • Removing the old factor before the new one is verified.
Lesson recap

Key takeaways

  • MFA methods differ in phishing resistance.
  • Recovery is part of setup.
  • Unexpected prompts require investigation, not approval.

Frequently asked questions

Is SMS MFA useless?

No. It is weaker than phishing-resistant methods but still adds protection over a password alone when stronger methods are unavailable.

What if I receive repeated login prompts?

Deny them, change the password through the official service, review sessions and verify that recovery information has not changed.

Evidence and updates

Sources and further reading

  1. Require Multifactor AuthenticationCISA
  2. SP 800-63B: Authentication and Authenticator ManagementNIST
  3. Turn On MFACISA
Finish this lesson

Ready to continue?

Mark the lesson complete so your Learning Path progress stays current on this device.