If you do only one thing from this course, do this. Two-factor authentication (2FA), also called multifactor authentication (MFA), is the single most powerful protection for your accounts. The U.S. government’s cybersecurity agency, CISA, urges everyone to turn it on for every important account.

What it is. Normally you log in with one thing: your password. 2FA adds a second step, so even if someone steals your password, they still cannot get in without the second factor. It is like needing both a key and a code to open a door.

The three kinds, weakest to strongest:

  • Text message code (SMS). A code is texted to you. This is the most common and far better than nothing, though texts can be intercepted.
  • Authenticator app. A free app (like Google Authenticator or Microsoft Authenticator) shows a 6-digit code that changes every 30 seconds. Stronger than text.
  • Passkeys. The newest and strongest option. A passkey uses your phone’s fingerprint or face unlock to sign in, with no password to steal. CISA calls this type “phishing-resistant,” because it will not work on a fake site. Use it wherever it is offered.

A quick example. A criminal buys your leaked password online and tries to log into your email. Your phone buzzes with a login request you did not start, so you tap “No.” They are locked out. Your password alone was not enough, because you had 2FA.

What to do:

  1. In your email settings, find Security, then 2-Step Verification (Gmail) or Two-step verification (Outlook), and turn it on.
  2. Choose an authenticator app or a passkey if offered; text codes are fine if that is easier to start.
  3. Save your backup codes somewhere safe (write them down or store them in your password manager) so you are never locked out.