Two factors are two different checks
The first factor is commonly something you know, such as a password. The second is something you possess, such as a phone or hardware key.
If an attacker learns the password, the second confirmation can still block access after a leak or phishing attempt.
Common options
- one-time codes from an authenticator app;
- approval on a trusted device;
- a hardware security key;
- SMS when stronger methods are unavailable.

Choose a resilient method
Authenticator apps work without a mobile network and are less dependent on phone-number security. Hardware keys offer strong phishing resistance where supported.
Never approve a request you did not initiate. Repeated unexpected prompts may be designed to make you accept by habit.
Keep a recovery path
- store backup codes offline;
- add another trusted factor if possible;
- update the setup when changing phones.
2FA does not replace other checks
A second factor does not make a fake page safe. A code entered on a phishing page can be used immediately by an attacker.
Always check the domain, use a unique password, and never share one-time codes in messages or calls.
FAQ
Should I give a 2FA code to support staff?
No. A one-time code belongs only in the sign-in form you opened yourself on a verified domain.
What if I lose my phone?
Use a previously stored backup code or another trusted factor, then remove the lost device from security settings.
