Two-Step Verification Explained: Which Method Should You Use?

Two-step verification protecting account sign-in on a laptop and phone

Updated:
10 September 2026 · Reading time: about 9 minutes

Two-step verification adds another proof of identity after—or instead of relying only on—a password. If someone steals your password, that extra check can stop them from entering your account. But the available methods do not all protect you in the same way.

Best beginner choice

Use the strongest method your important account and devices support. Passkeys or hardware security keys offer strong protection against phishing. For a Google Account, Google recommends prompts when you are not using a passkey. An authenticator app is a useful widely supported option. SMS is still better than a password alone, but it is more exposed to phone-number attacks. Always create a recovery plan.

What does two-step verification mean?

A password is something you know. A second step normally asks for something you have, such as a phone, authenticator app or security key. Some methods also use something you are, such as a fingerprint, to unlock a device-held credential.

You may see the terms 2-Step Verification (2SV), two-factor authentication (2FA) and multi-factor authentication (MFA). They are often used loosely. The important question is not the label; it is whether a stolen password alone is enough to sign in and whether the method resists a fake sign-in page.

NIST’s current authentication guidance distinguishes assurance levels and says higher-assurance services should offer phishing-resistant authentication. That matters because a traditional one-time code can still be typed into a convincing fake website, while a phishing-resistant cryptographic method is designed not to authenticate to the wrong site.

Methods compared

Method Main strength Main limitation Good fit
Passkey Phishing-resistant and no reusable secret to type Recovery and device-sync behaviour must be understood Important personal accounts on supported devices
Hardware security key Strong phishing resistance with a dedicated device Costs money and a spare or recovery method is wise High-risk accounts, creators and administrators
Device prompt Easy approval with useful device or location context A user can approve an unexpected prompt by mistake Google Accounts and other services that support prompts
Authenticator app code Works without mobile service and avoids SIM delivery A code can still be stolen by a live phishing page Broad compatibility and offline use
SMS or voice code Simple and widely available Exposed to phone-number attacks and message interception When stronger options are unavailable
Backup code Emergency access when a normal method is lost Anyone who obtains an unused code may be able to use it Recovery only—not daily sign-in

1. Passkeys: strong protection with less typing

A passkey uses a cryptographic credential held by your device or credential provider. You normally unlock it with the device screen lock, fingerprint or face check. Because you do not type a reusable password or code into the website, a fake site cannot simply capture that secret and replay it.

A passkey may replace the password-and-second-step sequence rather than act as a traditional second code. Google explains that signing in with a passkey bypasses its second authentication step because possession of the device is already verified.

Before creating one, understand where it will be stored, which devices can use it and how you will recover if a device is lost. Keep your device lock private and remove old devices from the account when you no longer control them.

2. Hardware security keys: a dedicated high-security option

A hardware security key is a small physical device used to prove that the person signing in has the registered key. Compatible keys can provide phishing-resistant authentication because the sign-in is bound to the genuine service.

This method is excellent for primary email, cloud administration, financial access or a public-facing account that would be costly to lose. Register a spare key or another carefully protected recovery method. Do not keep the only key and its only backup in the same bag.

3. Sign-in prompts: convenient, but read before tapping

A prompt appears on an already signed-in phone and asks whether you are trying to sign in. Google recommends prompts as a second step when a user chooses not to sign in with a passkey. Google says prompts can offer better protection than phone-number codes against SIM-swap and related attacks.

Convenience creates one danger: repeated unexpected prompts may pressure someone into tapping “Yes.” Only approve a prompt you personally caused. Check the device, location and time shown. If you did not initiate the sign-in, deny it, change a possibly exposed password through the official account page and review recent security activity.

4. Authenticator apps: useful even without mobile service

An authenticator app generates a short code that changes regularly. It usually works without an internet connection or mobile signal. This avoids dependence on receiving an SMS, which is useful while travelling or when a mobile network is unreliable.

The code is still a secret. A real-time phishing page can ask for it and immediately pass it to the genuine service. Always check the address before entering a code, and never tell a caller or support agent the code. Google states that it will not call to ask you to verify a code.

When setting up the app, record the recovery information offered by the account. If the authenticator supports encrypted backup or transfer, understand how it is protected before relying on it.

5. SMS and voice codes: better than nothing, not the strongest

A text or voice code adds a barrier when only the password has been stolen. However, the security of the step partly depends on the phone number. Criminals may attempt to move a number to another SIM, trick a carrier or intercept messages. Google’s help page notes that text and call codes can be vulnerable to phone-number-based attacks.

If SMS is the only option, use it. Also protect the mobile-carrier account with its own unique password and account PIN, remove public personal details that assist impersonation, and move to a stronger method when the service adds one.

6. Backup codes: your emergency key

Backup codes are one-time recovery secrets. They help when your phone is lost, an authenticator is unavailable or a prompt cannot arrive. They are not harmless because they are called “backup” codes: an unused code can grant access.

  • Generate them only from the genuine account-security page.
  • Store them away from the device you normally use.
  • Do not email, message or photograph them into an unprotected cloud gallery.
  • Never share one with a caller, chat agent or person claiming to verify your identity.
  • Generate a new set if the stored copy may have been seen or lost.

How to turn on Google 2-Step Verification

Google’s current computer instructions are:

  1. Open your Google Account.
  2. Choose Security & sign-in.
  3. Under How you sign in to Google, select Turn on 2-Step Verification.
  4. Follow the on-screen steps and add the methods available to your account.

A work or school administrator may control which methods are available. Do not attempt to bypass an organisation’s security policy; contact its administrator if the setting is unavailable.

Do this before you finish: add at least one recovery method that does not depend on the same phone, then test it while you still have normal access. Store backup material safely. A strong sign-in setup is incomplete if one broken or lost device permanently locks you out.

A sensible setup for most beginners

  1. First create a unique password and store it in a protected password manager.
  2. Use a passkey when the service, device and recovery model fit your needs.
  3. Otherwise choose a security key, a trusted device prompt or an authenticator app.
  4. Use SMS when it is the only practical second step, rather than leaving the account password-only.
  5. Create recovery codes and keep them separate from the everyday device.
  6. Review registered phones, keys and recovery addresses twice a year and after replacing a device.

If your phone is lost

  1. Use a trusted device that is already signed in, a spare security key or a backup code.
  2. Open the provider’s official account-security page directly.
  3. Remove the lost device or revoke its sessions.
  4. Contact the mobile carrier through a verified channel if the SIM or phone number is at risk.
  5. Change passwords if the unlocked device could reveal them.
  6. Replace consumed backup codes and register the new phone carefully.

Do not trust a phone number or recovery link from an unexpected message during this process. Search scams often target people who are already stressed about a locked account.

Common mistakes

  • Approving a prompt without checking whether you initiated it.
  • Reading a verification code to someone on a call.
  • Keeping the only recovery code on the phone it is meant to replace.
  • Registering a second step but leaving an old phone or address on the account.
  • Assuming every QR code is safe; a QR code can send you to a fake page.
  • Believing MFA makes phishing impossible. Some methods resist phishing better than others.

Frequently asked questions

Is SMS 2FA useless?

No. It is usually safer than using only a password, because a password thief also needs access to the second step. It is simply weaker than phishing-resistant methods and depends on the security of the phone number.

Can I use more than one method?

Often yes, and that can improve recovery. Make sure every enabled method is protected. An abandoned phone number or old device can become the weakest path into the account.

Should I use email as the second step?

It can help on some services, but it is not independent if the email account uses the same password or is already compromised. Secure the primary email first with a unique password and a stronger available second step.

What is the strongest method?

Phishing-resistant cryptographic methods such as properly implemented passkeys and hardware security keys provide important advantages. Your practical choice also needs safe recovery, supported devices and correct use.

Final checklist

  • Your primary email has a unique password and an additional sign-in method.
  • You know which method is used day to day and which is for recovery.
  • You never share prompts, codes or backup codes.
  • You deny unexpected prompts and review security activity.
  • Old phones, keys and recovery addresses are removed.
  • Your backup method is stored separately and has been tested.

Sources and review note

Editorial note: Features differ by provider and can change. This article explains the security trade-offs; use the current official help page for the exact menus on your account.

Comments

Popular posts from this blog

How to Create Strong Passwords Without Reusing Them

12 Online Safety Habits Every Beginner Should Use

What to Do If Your Online Account Is Hacked: 12 Immediate Steps