Step Two collects all your two-factor codes in one clean app, syncs via iCloud across all Apple devices, and autofills in Safari automatically. Available on Setapp.
How to enable two-factor authentication: Go to your account's Security settings, find Two-Factor Authentication or 2-Step Verification, add a trusted phone number or authenticator app, and confirm with a verification code. Done, your account is now protected with a second lock.
SMS codes are the weakest 2FA option. Text messages can be intercepted and are vulnerable to SIM-swapping attacks. Use an authenticator app whenever a service supports it.
Every major platform supports 2FA. Apple, Google, Instagram, X, WhatsApp, Amazon, Snapchat, TikTok, and Facebook all let you enable it in Security or Account settings — it takes under two minutes on most.
Step Twokeeps all your 2FA codes in one place. The app organizes time-based codes for every account, syncs via iCloud, and its Safari extension can autofill codes automatically — available on Setapp.
Pareto Securitymonitors your Mac's security settings automatically. It runs checks in the background, flags anything that needs attention, and gives you step-by-step fixes — so 2FA is just one part of a solid security setup.
Two-factor authentication (2FA) adds a second verification step when you sign in, a code from your phone, an authenticator app, or a hardware key, so that a stolen password alone can't unlock your accounts.
To prevent your online accounts from being hacked, it’s recommended to set up two-factor authentication (2FA), an important security measure that requires an extra step when you sign in to high-value services.
As technology advances, so do the tactics of internet scammers. It’s important to be very observant when using the internet; cybercriminals often rely on users’ lack of attention and their reluctance to protect private data with strong passwords.
In this post, I'll walk you through what 2FA is and show you how I set it up on different services. It's easier than you might think, so let's dive in.
Method
Security level
Best for
Main drawback
SMS codes
Low
Basic accounts when no other option exists
Vulnerable to SIM-swapping
Authenticator apps
High
Most online accounts
Need your device nearby
Hardware keys
Highest
Critical accounts (banking, email)
Can be lost or forgotten
Push notifications
Medium-High
Quick daily logins
Requires internet connection
Passkeys
Highest
Future-proof security
Tied to specific ecosystems (like Apple, Google, or Microsoft) — hard to switch between different platforms
Turn on two-factor authentication on your Apple devices
If you're ready to add an extra layer of security to your Apple account, here's how I recommend setting up two-factor authentication on iPhone, Mac and web.
To turn on two-factor authentication on iPhone and iPad:
Go to Settings > Apple Account > Sign-In & Security.
Tap Two-Factor Authentication.
Tap Add a Trusted Phone number, where you can receive verification codes.
Tap Continue and enter the verification code sent to your phone.
Apple will now require this extra verification step when you sign in from a new device.
To enable two-factor authentication on Mac:
Click Apple menu > System Settings.
Click Apple Account at the top, then click Sign-In & Security.
Click Turn On next to Two-Factor Authentication.
Follow the on-screen instructions to add a trusted phone number.
Enter the verification code when prompted.
Your Mac will now be protected with 2FA across all Apple services.
To manage two-factor authentication for your Apple Account on the web:
Add a trusted phone number and verify it with the code sent to you.
Once enabled, you'll need to verify your identity when signing in from new browsers or devices.
Turn on two-factor authentication for online accounts
You probably have login credentials for multiple online services that support 2FA. If you want to enable it, let me show you how to enable it on the most popular services.
Enable two-factor authentication on Google
Google accounts power many services, including Gmail, YouTube, and Google Drive. Here's how to secure them:
Click 2-Step Verification under How you sign in to Google.
Click Get Started and sign in again if prompted.
Choose your verification method (Google recommends using prompts on your phone).
Follow the setup instructions for your chosen method.
Enable two-factor authentication on X (ex Twitter)
X allows you to enable 2FA as well. Here’s how to do it:
Tap your profile icon and choose Settings and privacy.
Tap Security and account access > Security.
Tap Two-factor authentication.
Choose your preferred method: authentication app, text message (SMS), or security key.
Follow the setup instructions.
Note that X requires a paid subscription for SMS-based 2FA. If you don’t have a subscription, I recommend using an authenticator app instead.
Enable two-factor authentication on Instagram and Threads
To turn on 2FA on Instagram (or Threads), follow these steps:
Tap the menu icon in the top right corner of your profile.
Tap Accounts Centre > Password and security.
Tap Two-factor authentication > Choose either your Instagram or Threads account you want to secure.
Choose Authentication app or SMS WhatsApp.
Follow the prompts to complete setup.
Instagram will now require verification when you log in from new devices.
Enable two-factor authentication on TikTok
To turn on 2FA on TikTok:
Tap the menu icon in the top right corner of your profile.
Tap Settings and privacy > Security > 2-step verification.
Choose SMS or Authentication app.
Follow the on-screen instructions.
TikTok's 2FA helps protect your account from unauthorized access.
Enable two-factor authentication on YouTube
Your Google account is linked to your YouTube account, so 2-step verification will already be on there. Once you've enabled it for Google, it automatically protects YouTube too.
Enable two-factor authentication on Snapchat
To turn on 2FA on Snapchat:
Tap the gear icon in your profile.
Tap My Account.
Tap Two-Factor Authentication > Choose Let’s do it.
Choose SMS Verification or Authentication App.
Follow the setup steps.
Snapchat will text or generate codes when you sign in from new devices.
Amazon's 2FA protects your shopping account and any connected services.
Keep track of your security with these two tools
Two-factor authentication is an important security measure, but you need a top-notch data monitoring tool to protect all of your accounts.
First tool: Pareto Security. The app keeps track of your security settings and makes sure you have the best protection enabled. It simply runs automatic security checks on your Mac and monitors over 20 security settings and alerts you when something needs attention.
Here's how to use Pareto Security for security monitoring:
Open Pareto Security from your menu bar.
Click Run checks.
Review any orange-marked items that need fixing.
Click each issue for step-by-step resolution instructions.
Second tool:Step Two. The app neatly organizes all of your two-factor codes, making them simple to copy and paste. Its Safari extension can even autofill codes automatically.
Two-factor authentication (2FA) is a security method that requires two different forms of identification before you can access an account.
The three factors typically include:
Something you know (like your password)
Something you have (like your phone or authenticator app)
Something you are (like your fingerprint or face)
The most common way 2FA happens is when you sign in from a new phone, tablet, computer, or location that the website doesn’t recognize. In such a case, the website will send you an SMS code that you have to enter before you can finish signing in. This extra step stops hackers who might have stolen your password but don't have access to your second factor.
However, SMS is the least secure 2FA method. First of all, the thief will have access to all of your accounts if your phone is stolen. Additionally, SMS communications are susceptible to hacking, and a thief can easily convince your mobile provider to provide them with a SIM card for your account — a technique called SIM-swapping.
Authenticator apps work the same way by giving you codes that refresh every 30 seconds. You can use them to prove that you are logging into a website from a new place or device. These apps can be installed on any device. Security experts favor authenticator apps because they don’t rely on a mobile signal and aren’t vulnerable to SIM-swapping attacks.
These apps store your account credentials locally and generate codes using an algorithm. Modern authenticator apps also support push notifications for one-tap approval and hardware security keys for maximum protection. According to NIST guidelines, authenticator apps provide stronger security than SMS-based methods.
Two-factor authentication: How to enable and stay safe online
I've seen how creative hackers can be when cracking passwords. That's why I always use strong, complex passwords, but I've learned that even that might not be enough. Enable two-factor authentication on every account that supports it, especially banking, email, and social media.
Until passkeys become universal, 2FA remains your best defense against account takeover.
Step Two makes managing your 2FA codes much simpler. Pareto Security ensures your Mac's security settings stay properly configured.
2FA is set. Now make sure everything else on your Mac is locked down too. Step Two and Pareto Security are both in Setapp's 270+ app library. Risk-free 7-day trial. Start My Free Trial.
FAQ
What happens when I enable two-factor authentication?
After enabling 2FA, you'll enter your password as usual when signing in. Then you'll receive a code via SMS, authenticator app, or push notification. Enter this code to complete sign-in. Most services remember trusted devices so you won't need codes for every login on your personal devices. New or unrecognized devices will always require the extra verification step.
How do I check if 2FA is already turned on for my account?
For Apple devices, go to Settings > Apple Account > Sign-In & Security and look for Two-Factor Authentication status. For Google accounts, visit myaccount.google.com/security and check the 2-Step Verification section. Most other services show 2FA status in their Security or Privacy settings. Look for terms like "two-factor," "2FA," or "two-step verification."
Can I turn two-factor authentication off later?
Yes, most services let you disable 2FA through security settings. Apple requires 2FA to remain on for 14 days after enabling before you can turn it off. However, disabling 2FA significantly increases your vulnerability to account takeover. Consider using Step Two to make 2FA more convenient rather than turning it off entirely.
Superpowers for your Mac
Tackle your tasks with dozens of helpful apps on Setapp.