Websites and Tech

Two-Factor Authentication (2FA)

Also called 2FA, multi-factor authentication, MFA, two-step verification

A login that requires two different kinds of proof, such as a password plus an app code or passkey, so a stolen password alone is not enough.

Quick facts: Two-Factor Authentication (2FA)

Category
Websites and Tech
Also called
2FA, multi-factor authentication, MFA, two-step verification
Level
Beginner
Affects
Account security, ad account and Business Profile takeover risk, Cyber Essentials compliance
Where to see it
Authenticator apps, passkeys, hardware security keys, WordPress 2FA plugins, account security settings
In this article4
  1. How two-factor authentication works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

Two-factor authentication (2FA) is a login method that asks for two different kinds of proof before letting someone in: usually something you know, such as a password, and something you have, such as your phone or a security key. A stolen password alone is then no longer enough to get into the account.

How two-factor authentication works

After you enter your password, the service asks for a second factor. The common options, roughly from weakest to strongest, are:

  • Text message codes. A six-digit code sent by SMS. Better than nothing, but vulnerable to SIM-swap fraud, where a criminal persuades a mobile network to move your number to their SIM.
  • Authenticator apps. Apps such as Google Authenticator or Microsoft Authenticator generate a new code every 30 seconds from a secret shared once when you set it up.
  • Push prompts. The service sends an approval request to an app on your phone.
  • Passkeys and hardware security keys. These use cryptography tied to the genuine website, so they cannot be phished on a fake login page.

Multi-factor authentication (MFA) is the broader term for any login using two or more factors; the National Cyber Security Centre (NCSC) calls it two-step verification. When you enable it, services also give you recovery codes for the day you lose your phone. Keep those somewhere safe and offline.

Why it matters

Passwords leak through data breaches, phishing emails and reuse across sites, and automated brute-force attacks try common ones against login pages all day. A second factor stops most of these attempts even when the password is known.

For a business, the accounts at risk are not just email. Your Google account may control Google Ads, Analytics, Search Console and your Business Profile; your Meta account controls your Facebook Page and ad account; your WordPress admin controls the website itself. A hijacked ad account can spend your budget on someone else’s adverts within hours, and recovering a lost Business Profile can be slow. Google Ads already asks for two-step verification before some sensitive account changes.

In the UK, the NCSC recommends switching on two-step verification for important accounts, and Cyber Essentials requires MFA on cloud services wherever the service offers it. If a breach exposes customer data, the ICO will look at whether basic measures like this were in place under UK GDPR.

Common mistakes

  • One shared login with one person’s phone as the second factor. When that person is on holiday or leaves, nobody can get in. Give each person their own login with appropriate access levels.
  • Losing recovery codes. A replaced phone without recovery codes can lock you out of a business account permanently.
  • Protecting email but not the website. WordPress has no built-in 2FA; it needs a reputable plugin.
  • Approving push prompts you did not start. Attackers send repeated prompts hoping someone taps approve to make them stop.
  • Relying on SMS for the most important accounts when an app, passkey or security key is available.

How to act on it

List the accounts that would hurt most if lost: email, domain registrar, hosting, website admin, Google, Meta, accounting software. Turn on 2FA for each, using an authenticator app or passkey where offered, and store recovery codes in a password manager or a locked drawer. Make sure at least two trusted people in the business can recover each critical account.

For your website, add 2FA for every administrator and editor, remove accounts that are no longer needed, and keep plugins patched with each security patch. Tightening admin access is a standard part of my WordPress SEO setup, because one stolen admin password can undo months of work on the site.

Do and do not

Do

  • Use an authenticator app, passkey or security key where offered
  • Store recovery codes safely offline
  • Give each person their own login

Do not

  • Share one login tied to one person's phone
  • Approve login prompts you did not start
  • Leave website admin accounts without 2FA

Questions people ask about this

Is two-factor authentication the same as multi-factor authentication?

Two-factor authentication is a type of multi-factor authentication that uses exactly two factors. Multi-factor authentication covers any login using two or more, such as a password, a phone and a fingerprint. In everyday use, including in Cyber Essentials and NCSC guidance, the terms are often used interchangeably.

What happens if I lose my phone with 2FA on it?

Use the recovery codes you saved when you set up 2FA, or a second registered device or security key. If you have neither, you will have to go through the service's account recovery process, which can be slow and is not always successful for business accounts. Setting up a backup method on day one avoids this.

Should I use text message codes for 2FA?

SMS codes are much better than no second factor, so use them if nothing else is offered. Where an authenticator app, passkey or hardware key is available, choose that instead, because text messages can be intercepted through SIM-swap fraud. For your email, domain registrar and ad accounts, it is worth the extra minute of setup.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.