Two-factor authentication (2FA) — why you should turn it on
A password alone is one lock on the door. Two-factor authentication adds a second one — and that's usually what stops the break-in.
Forms of 2FA you'll come across
What 2FA actually is
It's an extra step at login — besides your password, you confirm it's really you, usually with a code from your phone. Even if someone learns your password, they still can't log in without that second factor.
A code from an authenticator app
An app on your phone generates a code that changes every so often, which you type in at login. It works even without an internet connection and is one of the most common, convenient options.
SMS code — better than nothing, not perfect
A code sent by text is simpler to use, but in theory it can be intercepted if someone takes over your phone number. As a first step toward 2FA, it's still far better than having no second factor at all.
Security key — the strongest option
A small physical device you plug into your computer or tap against your phone, confirming your identity without typing a code. Less common in small businesses, but the hardest to bypass.
Why this works even when a password leaks
Password leaks usually aren't the user's fault at all — a database at some website ends up in the wrong hands, and the leaked passwords keep circulating from there. 2FA means a password alone is no longer enough to take over an account.
When it's a job for IT
- You're not sure whether 2FA is even enabled on your work email account
- You've lost the phone or key you used for two-factor login
- You received a login confirmation request (text, notification) that you never initiated
- You want to require 2FA for every employee across company systems
Want to turn on 2FA across your company systems?
Report the issue — it goes straight into our ticketing system, and our AI assistant assesses priority right away.