A stolen password can still get someone into your email, cloud storage, social accounts, shopping accounts, and password manager. Two-factor authentication adds another sign-in check, and the right setup takes only a few minutes once you know where each company hides the switch.
Start with the accounts that control the most data.
Then add stronger options like an authenticator app, passkey, or physical security key where the account supports them.
1. Start with an authenticator app
Install Google Authenticator, Microsoft Authenticator, Bitwarden Authenticator, or 1Password.
Open the account you want to protect and go to Security, Password and security, or Two-factor authentication.
Choose Authentication app, Use an app, or Set Up App.
Scan the QR code with your authenticator app.
If the service gives you a manual key instead, choose Enter code manually, Secret key, or Setup key in the authenticator app.
Enter the one-time code from the app into the account setup screen.
Save any Recovery codes before you close the setup page.
2. Turn on Google and Apple protection
This fixes the accounts that protect email, backups, apps, photos, and saved passwords.
For Google, open your Google Account, go to Security & sign-in, find How you sign in to Google, select Turn on 2-Step Verification, then follow the on-screen steps.
After Google 2-Step Verification is enabled, add a stronger sign-in method from the account prompts by choosing Passkey or Security key.
For Apple on iPhone or iPad, open Settings, tap your name, tap Sign-In & Security, turn on Two-Factor Authentication, then follow the onscreen instructions.
For Apple on Mac, open System Settings, click your name, click Sign-In & Security, turn on Two-Factor Authentication, then follow the onscreen instructions.
For Apple on the web, sign in at account.apple.com, complete the email code or security-question prompt, select Upgrade Account Security, then follow the onscreen instructions.
3. Secure Microsoft, Dropbox, and Amazon
For Microsoft, sign in to account.microsoft.com/security, select Manage how I sign in, go to Additional security and Two-step verification, choose Turn on, then follow the instructions.
To add Microsoft Authenticator, return to Manage how I sign in, select Add a new way to sign in or verify, choose Use an app, open Authenticator, tap the plus icon, select Personal account, then tap Scan a QR Code.
For Dropbox, log in to dropbox.com, click your avatar, open Settings, choose the Security tab, toggle 2-factor authentication to On, re-enter your password, then choose Text message or Authenticator app.
For Dropbox with an authenticator app, select Use an authenticator app, scan the QR code or add the Secret key, select Next, enter the 6-digit code, select Next, save your recovery codes, then choose Finish.
For Amazon, open Your Account, choose Login and security, select Edit beside Two-Step Verification Settings, choose Get Started, then follow the on-screen instructions.
4. Use Apple Passwords as your code generator
On iPhone, Apple Passwords can generate verification codes for websites and apps that support authenticator-app setup.
On the website or app, turn on two-factor authentication, choose Authenticator app, scan the QR code with your iPhone camera, then select the matching saved account.
For manual setup, use Passwords > All > your account > Edit > Set Up Code > Use Setup Key, then enter the generated code back on the website or app.
5. Lock down Facebook, Instagram, and X
This fixes the social accounts people lose through reused passwords and fake sign-in pages.
For Facebook on the web, click your profile picture, open Settings and privacy, choose Settings, go to Accounts Center, open Password and security, select Two-factor authentication, choose your Facebook account, then pick Authentication app, Text message, or Security key.
For Facebook in the app, open Menu, go to Settings, choose Accounts Center, open Password and security, tap Use two-factor authentication, select the Facebook account, choose Authentication app, then scan the QR code or enter the Setup key.
For Instagram, open Profile, go to Accounts Center, choose Password and security, tap Two-factor authentication, select the account, choose Authentication app, WhatsApp, or Text message, then follow the prompts.
For X on desktop, open the side menu, choose More, open Settings and privacy, go to Security and account access, choose Security, select Two-factor authentication, then choose Text message, Authentication app, or Security key.
For X with an authentication app, select Authentication app, choose Start, enter your password, select Verify, confirm your email, choose Link app now, scan the QR code, select Next, enter the generated code, select Verify, then choose Got it.
6. Strengthen Coinbase and 1Password
For Coinbase, sign in to the 2-step verification settings page, then use Available Methods > Authenticator app > Set up and follow the prompts with your authenticator app.
Coinbase also supports Security Key, Passkey, Push Notification, and Text message SMS; Coinbase calls SMS the default and least secure option.
For 1Password, sign in to 1Password.com and use your name > Manage Account > More Actions > Manage Two-Factor Authentication > Set Up App.
Write down the 16-character secret next to the QR code and store it somewhere safe, because that is your backup if you lose the authenticator.
Then scan the QR code with a separate authenticator app, select Next, enter the six-digit code, and select Confirm.
This needs a 1Password membership and 1Password 7 or later, or 1Password 6.8 for Mac.
7. Add a passkey or physical security key
For Google, use Chrome, Firefox, or Safari 13.0.4 or higher, enroll the security key, then connect it by USB, NFC, or Bluetooth when prompted.
For Apple on iPhone or iPad, open Settings, tap your name, open Sign-In & Security, tap Two-Factor Authentication, choose Security Keys, tap Add Security Keys, then follow the onscreen instructions.
For Apple on Mac, open System Settings, click your name, choose Sign-In & Security, click Two-Factor Authentication, go to Security Keys, click Set Up, then follow the onscreen instructions.
For Microsoft, sign in to account.live.com/proofs/manage, choose Add a new way to sign in or verify, select Face, Fingerprint, PIN, or Security Key, then follow your device prompts.
For Dropbox, log in to dropbox.com, click your avatar, open Settings, choose the Security tab, then use Passkeys > Add passkey or 2-factor authentication > Security keys > Add.
For Amazon, open Your Account, go to Login and security, select Set up beside Passkeys, then follow the device or browser prompts.
For Apple security keys, have at least two FIDO Certified keys ready before you start.
Apple also requires two-factor authentication on your Apple Account and iOS 16.3, iPadOS 16.3, or macOS Ventura 13.2 or later on every device signed in to that account.
8. Use SMS only when stronger methods are unavailable
Choose Authentication app, Passkey, or Security key first when the account offers one.
For Instagram, open Profile, go to Accounts Center, choose Password and security, tap Two-factor authentication, pick the account, choose Text message, enter or confirm your phone number, then enter the confirmation code.
For Dropbox, choose Use text messages during setup, enter the phone number that should receive codes, select Next, then enter the code you receive.
For Coinbase, open the 2-step verification settings page, toggle Text message SMS on, add a phone number, then enter the 6-digit code sent to that number.
For X, choose Text message under Two-factor authentication, enter your password, select Verify, confirm your email when prompted, enter the texted confirmation code, then select Got it.
9. Check managed account limits
For Google work, school, or group accounts, ask a Google Workspace super administrator to allow or configure 2-Step Verification from Google Admin console > Security > Authentication > 2-step verification.
For Microsoft work or school accounts, MFA can be required through Microsoft Entra admin center > Entra ID > Conditional Access > Policies, which needs a Microsoft Entra ID P1 license or a qualifying plan such as Microsoft 365 Business Premium; security defaults are the alternative available to all customers.
For Dropbox teams, an admin can require it from Admin console > Settings > Security > Authentication > 2-step verification, but each team member still completes setup.
For Managed Apple Accounts, do not use the Apple physical Security Keys setup because Apple does not support it for those accounts.
When a personal-account option is missing or disabled, use the admin path for that service.
Frequently Asked Questions
Which 2FA method should I turn on first?
Turn on an authenticator app first when the account supports it. Add a passkey or physical security key next for accounts that offer those stronger sign-in options.
Can one authenticator app protect different accounts?
Yes. Microsoft Authenticator, Google Authenticator, Bitwarden Authenticator, and 1Password can store one-time codes for services that support QR-code or setup-key authenticator setup.
Does Dropbox let me set up 2FA in the mobile app?
No. Dropbox says 2FA setup must be done on dropbox.com. After it is enabled, you can add backup methods from the web security settings.
Can I use a passkey instead of a second code?
On Google, yes. After 2-Step Verification is set up, Google lets you sign in with your password and a second step or with your passkey, because the passkey verifies device possession.