Home / Guides / Guide

How to Set Up Two-Factor Authentication Properly

2026-09-16 · SoftVault team

Anyone can enable 2FA. Doing it so you do not lock yourself out, or get phished anyway, takes a few extra minutes on the right five accounts.

Two-factor authentication is the highest-value twenty minutes you can spend on your accounts, and most people do it in the way that fails first: a text message code with no backup. The goal is a second factor that an attacker cannot obtain remotely and that you can still use if your phone dies.

Rank the methods

Setting up an authenticator app correctly

  1. Install the authenticator app on your main phone, and a second one on a tablet or a spare device if it supports syncing.
  2. Scan the QR code on the site's security page and confirm the six-digit code works before you close the window.
  3. Write the recovery codes on paper immediately. Do not screenshot them and do not store them in the same password manager entry they unlock.
  4. Check whether the site lets you enroll a second method or a second device, and do it now rather than after a phone replacement.
  5. Store the recovery codes in two places, at least one offline, and confirm they are readable months later.
  6. Test one code entry, log out, and log back in to prove the whole chain works end to end.

Where it goes wrong

Where the codes really get stolen

Modern attacks do not break the second factor, they relay it: a fake login page forwards your password and your code to the real site while you watch it work. That is why hardware keys and passkeys matter so much, and why a code typed into a page you reached by clicking a link is only as safe as the link. Add a password manager so each account has a unique password, and on exchange accounts turn on address whitelisting so a stolen session still cannot withdraw.

Do it in this order: email, password manager, bank, exchange, cloud storage. Five accounts, and everything else gets easier to recover.