Use 2-step verification on important accounts, but design recovery before you need it: no account should depend entirely on one phone, one SIM or one authenticator installation.
Choose the strongest practical method
| Method | Main consideration |
|---|---|
| Passkey or FIDO security key | Strong phishing resistance when supported |
| Authenticator app | Works without mobile signal, but migration and recovery must be planned |
| App prompt | Convenient, but protect the trusted device and review every request |
| SMS code | Better than password alone, but exposed to number loss and SIM-swap risk |
| Backup code | Emergency recovery; usually single-use and must be stored safely |
Start with the accounts that unlock everything else
- primary email;
- Apple Account or Google Account;
- password manager;
- banking and payment accounts;
- mobile-network account;
- social media used for identity or business.
Build independent recovery
- Add a current recovery email and trusted number.
- Generate backup codes where offered.
- Keep codes outside the phone.
- Register a second trusted device or security key where appropriate.
- Test one recovery route before replacing the old phone.
Never approve an unexpected request
A genuine support agent should not ask you to read out a one-time code that arrived because someone is signing in. Open the official app or type the known website address yourself.
Remove the single point of failure before adding more factors
Strong authentication can still fail operationally if the same phone holds the password manager, SIM, authenticator, passkey and only recovery code. Build at least one recovery route that remains available when the phone is lost.
- Use phishing-resistant options such as passkeys or security keys where practical.
- Keep backup codes or a spare key in a separate secure location.
- Maintain current recovery contact details and review trusted-device lists.
- Test recovery before replacing, repairing or wiping the main phone.
The objective is not the highest number of factors. It is a secure sign-in process that the legitimate owner can still complete without weakening it during an emergency.
Choose the safest setup path
Use this section to add stronger sign-in protection without creating a single point of failure on the same phone being protected.
- Compare or decide: Best Ways to Store Backup Codes; SMS 2FA vs Authenticator App: Which Is Safer?.
- Set up or change: How to Move Authenticator Apps to a New Phone; How to Set Up 2FA on Apple ID; How to Set Up 2FA on Banking Apps; How to Set Up 2FA on Google Account; How to Set Up 2FA on Social Media Accounts; How to Set Up Two-Factor Authentication; How to Use a Hardware Security Key with Your Phone.
- Fix or recover: How to Recover Accounts Without Backup Codes.
- Use the focused guide: Passkeys: What They Are and How to Use Them; What to Do If You Lose Your Authenticator App.
When this hub has done its job
At least one tested recovery method should exist outside the primary phone before any old authenticator, trusted device or security key is removed.
