Turning on multi-factor authentication takes a few minutes per account. Doing it properly takes two extra steps, and they are exactly the ones almost everybody skips: saving the recovery codes and registering a second method.
This post sets out the full procedure, in the order that actually reduces risk. It is the operational side of the recommendation protecting accounts with a second factor.
The order matters more than it seems
There is one dependency that decides the sequence: recovery for almost every account runs through email.
That means protecting the cloud or the bank while leaving the mailbox exposed does little: whoever gets into the mailbox can start recovery on the other services and, in many cases, work around the MFA you enabled there.
The correct order is therefore:
- main email — it is the root of everything;
- password vault — it protects dozens of credentials at once;
- bank and payment services;
- cloud and document archives;
- work accounts and digital identity;
- social networks;
- everything else, as you go.
If you have twenty minutes, spend them on the first two.
1. Prevention: turning the second factor on
Choose the best method the service offers
What to do. In order of preference:
| Method | When to choose it |
|---|---|
| Hardware key or passkey | If the service supports it and the account is critical: the most solid protection |
| Authenticator app | The good compromise for most accounts |
| Push notification | Convenient, but requires care not to approve out of habit |
| Text message | Only if it is the sole option available — better than nothing, but the most fragile method |
The detailed comparison is in the post on which second factor to choose.
Install a transferable authenticator app
What to do. Choose an app that allows the codes to be exported or synced to a new device. It is the most important criterion in the choice, and the least considered: an app that ties the codes to one phone turns a broken phone into the loss of every access.
Where to find the setting. In the account settings, look for “Security”, “Sign-in and security”, “Two-step verification” or “Two-factor authentication”.
Save the recovery codes — right away
What to do. During setup, the service shows a list of one-time codes. Do not close that screen without saving them. They are shown once only.
Where to keep them. Printed, somewhere safe at home or at the office. Or in a password vault — but only if that vault is not protected by the same second factor you are configuring.
Where not to keep them. In a note on the same phone. In a photo in the gallery. Inside the account they are protecting.
Register a second method
What to do. Where the service allows it: a second device with the authenticator app, a spare hardware key, or an alternative phone number.
Why it counts. It is the fastest way back in if you lose the first device, and it saves you going through the recovery procedures.
Check that it works
What to do. Sign out of the account and back in once, completing the second step. This is to understand the flow while you are calm, rather than in a moment of urgency.
2. Detection: reading the signals a second factor produces
A second factor does not only protect: it informs. Every sign-in attempt with the correct password generates a request that reaches you.
Treat every unexpected request as a signal
What to do. If you receive a verification request you did not start, do not approve it — and do not simply ignore it either. It means somebody has your password: it needs changing.
Never approve out of habit
What to do. Push notifications are confirmed with a single tap, and for exactly that reason they get approved absent-mindedly. Before confirming, always ask yourself: am I signing in to something right now?
Where the service allows it, prefer the method that requires typing a number shown on screen rather than a simple “approve”: it makes automatic confirmation impossible.
Check the registered methods
What to do. Every few months, check which authentication methods are associated with your accounts. A method added that you do not recognise is a serious signal: it is there to keep access even after a password change.
The full list of indicators is in the post unexpected verification requests.
3. Response: what to do when something does not add up
The order, here too, decides the outcome.
- Do not approve the request. It is the first and most important step.
- Change that account’s password, from a device you trust. The request you received says precisely that the password is known.
- Check the registered authentication methods and remove any you do not recognise.
- Regenerate the recovery codes: the previous ones may have been seen.
- Revoke unrecognised sessions and devices, after the password change.
- Look at where you had used that password or a variant of it, and change it there too.
4. Recovery: if you have lost the second factor
- Try a second device where the account is already signed in: often the fastest route.
- Use the recovery codes, if you saved them.
- Check whether you registered an alternative method: a second device, a key, a number.
- Start the service’s official recovery procedure, if none of the above works. Be ready for identity checks and timelines that can exceed a week.
- Start again from the main email: once that is recovered, the other accounts become simpler.
- Reconfigure MFA on the new device and, this time, save the codes.
The concrete consequences of this scenario are described in losing access to your second factor.
A plan in two sessions
Session 1 — The root (20 minutes)
- Turn on MFA for your main email, with an authenticator app.
- Save the recovery codes, outside the phone.
- Register a second method, if available.
- Do the same for the password vault.
With that one session you have protected the two accounts everything else depends on.
Session 2 — Money, documents, work (20 minutes)
- Turn on MFA for bank and payment services.
- Then for cloud and work accounts.
- Save the recovery codes for each, in the same place as the first ones.
- Write down somewhere which accounts have MFA enabled: you will need it if you ever have to recover them.
Where to find the setting, service by service
The names change, the location almost never does. It usually takes three steps.
| Step | What to look for |
|---|---|
| 1. Open your profile | The icon with your initial or your photo, top right |
| 2. Go into settings | “Settings”, “Account”, “Manage your account” |
| 3. Find the security section | “Security”, “Sign-in and security”, “Privacy and security” |
Inside that section, the option to enable is called one of these:
- Two-step verification — the most widespread wording;
- Two-factor authentication or 2FA;
- Multi-factor authentication or MFA;
- Two-step sign-in, Login verification, Two-factor login.
They are all the same thing. If you cannot find it, search the service’s help centre for “two-step verification” together with the service’s own name.
A note on banking services. On banks and payments, strong authentication is often already compulsory by law and built into the app. In that case there is nothing to enable: do check, though, that the method is the bank’s app and not a text message, where you have the choice.
The particular case of the password vault
It deserves a note, because it is the one account where the configuration needs extra care.
The password vault holds the credentials to everything else — including, often, the recovery codes for other services. Two rules follow:
- The vault’s recovery codes cannot live in the vault. They have to be kept outside: printed, somewhere safe.
- Consider keeping the vault’s second factor separate from the app you use for everything else. If the authenticator app and the vault sit on the same phone, that phone becomes a single point of dependency.
It is the account where investing in the most solid method available makes most sense: if the service supports a hardware key, this is where to use one.
Frequent mistakes
- Skipping the recovery codes. The mistake that produces almost every lockout.
- Keeping them in the wrong place. On the phone, or in the account they protect: they will not be available when needed.
- Choosing a non-transferable app. It turns a broken phone into a much bigger problem.
- Enabling MFA everywhere except email. It leaves the recovery door open.
- Approving notifications out of habit. It turns the protection into a formality.
- Stopping at text messages when better options exist. A good starting point, a poor destination.
- Not testing the flow. Discovering how it works at the moment of need is the worst condition.
- Changing phone without transferring first. It has to be done while the old device still works.
Operational checklist
Stage 1 — The root
- ☐ MFA enabled on the main email
- ☐ MFA enabled on the password vault
- ☐ Recovery codes for both saved outside the phone
Stage 2 — What matters
- ☐ MFA enabled on bank, cloud and work accounts
- ☐ Recovery codes saved for each
- ☐ Second method registered where possible
Stage 3 — Continuity
- ☐ The authenticator app allows transfer
- ☐ I have a list of the accounts with MFA enabled
- ☐ I know what to do, and in what order, if I lost my phone
Stage 4 — Maintenance
- ☐ Registered authentication methods checked in the last six months
- ☐ Recovery contact details up to date
- ☐ No verification request approved without having started it
A short scenario
John has to change phone. Before retiring the old one, he does three things.
He opens the authenticator app and exports the codes to the new device, while both are working. He checks he has the recovery codes for his main accounts. He verifies that he can reach his email from the new phone.
Only then does he wipe the old device.
Ten minutes, in the right order. Had he wiped it first, he would have had to recover every account through the official procedures.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Configuring the second factor completely, recovery included |
| Awareness | Understanding why email has to be protected before any other account |
| Secure Behaviour | Never approving a request you did not start, not even to clear the notification |
Reference level: FL2 — Beginner for enabling it, FL3 — Autonomous for handling recovery and device changes.
Conclusion
Turning on multi-factor authentication is the single action that most reduces the overall risk to your accounts. It takes a few minutes, and it should start from email.
The one step not to skip is the recovery codes. Skip it and you are swapping one risk for another.
What to do right now. Turn MFA on for your main email, and save the recovery codes before closing the screen. It is the best-spent quarter of an hour in this whole series.
To see where you stand, the digital resilience self-assessment gives you a reference point.
Related content
- Protecting accounts with a second factor — the recommendation this belongs to
- Which second factor to choose — how to choose between text messages, apps, push and keys
- Unexpected verification requests — what to watch in order to notice in time
- Losing access to your second factor — what the recovery codes prevent
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



