Set up and review MFA on your own account
Turn on app-based multifactor authentication for an account you own, store the recovery codes safely, and review its sign-in activity.
Environment
An online account you own (email, cloud storage, etc.) and an authenticator app on your phone.
Before you start
- Read Multifactor Authentication (p.85), Soft Authentication Tokens (p.90) and Passwordless Authentication (p.91).
You will
- Enrol a TOTP authenticator
- Store recovery codes securely
- Identify the authentication factors in use
Steps
-
1
Open the account's security settings and choose two-step verification with an authenticator app.
-
2
Scan the QR code with your authenticator app and enter the 6-digit code to confirm.
-
3
Save the recovery codes in a password manager or print them and store them somewhere safe.
-
4
Sign out and back in to test it. Note which factor types you used: something you know, have, or are.
-
5
Open the account's recent sign-in or device activity page and check for anything you don't recognise.
-
6
If the account supports passkeys or a hardware security key, read what it offers and note how that differs from a TOTP code.
Check your understanding
- ?Why is an authenticator app stronger than SMS codes?
- ?Which factor types does 'password + authenticator app' combine?
- ?What makes FIDO2/passkeys resistant to phishing?