Guide · IT Security

Two-factor authentication (2FA) — why you should turn it on

A password alone is one lock on the door. Two-factor authentication adds a second one — and that's usually what stops the break-in.

Forms of 2FA you'll come across

1

What 2FA actually is

It's an extra step at login — besides your password, you confirm it's really you, usually with a code from your phone. Even if someone learns your password, they still can't log in without that second factor.

2

A code from an authenticator app

An app on your phone generates a code that changes every so often, which you type in at login. It works even without an internet connection and is one of the most common, convenient options.

3

SMS code — better than nothing, not perfect

A code sent by text is simpler to use, but in theory it can be intercepted if someone takes over your phone number. As a first step toward 2FA, it's still far better than having no second factor at all.

4

Security key — the strongest option

A small physical device you plug into your computer or tap against your phone, confirming your identity without typing a code. Less common in small businesses, but the hardest to bypass.

Why this works even when a password leaks

Password leaks usually aren't the user's fault at all — a database at some website ends up in the wrong hands, and the leaked passwords keep circulating from there. 2FA means a password alone is no longer enough to take over an account.

When it's a job for IT

  • You're not sure whether 2FA is even enabled on your work email account
  • You've lost the phone or key you used for two-factor login
  • You received a login confirmation request (text, notification) that you never initiated
  • You want to require 2FA for every employee across company systems

Want to turn on 2FA across your company systems?

Report the issue — it goes straight into our ticketing system, and our AI assistant assesses priority right away.

Report an issue

← Back to the Guide