Why this matters
Multi-factor authentication (MFA) means you need something extra, like an approval on your phone, as well as your password to sign in. If a criminal steals your password, MFA usually stops them getting in. It is one of the most effective security steps you can take.
What you'll need
- Access to the account you want to protect
- A smartphone
- An authenticator app such as Microsoft Authenticator or Google Authenticator
Step-by-step instructions
Step 1
Install an authenticator app
Download Microsoft Authenticator or Google Authenticator from the official App Store or Google Play. Authenticator apps are more secure than SMS codes, which can be intercepted through SIM-swap scams.
Step 2
Open the account security settings
Sign in to the account on a computer and look for "Security", "Sign-in & security", "Two-step verification" or "Login settings".
Step 3
Choose the authenticator app option
Select "Authenticator app" (sometimes called "Authentication app" or "TOTP"). The site will show a QR code.
Step 4
Scan the QR code
In your authenticator app, tap the add (+) button and scan the QR code. The app will start showing a six-digit code that changes every 30 seconds.
Step 5
Confirm with a code
Type the current code from the app into the website to finish setup.
Step 6
Save your recovery codes
Most services give you backup or recovery codes. Store them somewhere safe and offline so you can get in if you lose your phone.
Frequently asked questions
Is SMS good enough for MFA?
SMS is much better than no MFA, but an authenticator app or security key is stronger because SMS codes can be stolen through SIM-swap scams.
Summary
Turning on MFA for your email, banking and work accounts blocks the vast majority of password-based attacks.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.