Skip to content
Let’s plan the right software for your processes. Call us for a demo or a quote: +90 546 737 48 29

TR EN DE

What is two-factor authentication and how do you turn it on?

Two-factor authentication (2FA) asks for a second proof in addition to your password when you sign in to your account: a code sent to your phone, a code from an authenticator app, or a security key. Even if your password is stolen, the attacker cannot get past this second step, so your account stays protected. We recommend turning it on for your email, cloud storage, bank and social media accounts.

In brief

  • Two-factor authentication protects your account even if your password is stolen.
  • You turn it on in the account's Security settings; choose an authenticator app or a security key if you can.
  • Keep your recovery codes in a safe place.
  • Never tell anyone who asks for it your verification code.

What you need

  • Your account password
  • Your phone and, if possible, an authenticator app
  • A safe place to keep your recovery codes

Note

Menu names vary by service and change with updates; the routes below are general guidance.

On this page

Steps to turn on two-factor authentication

  1. Open your account's security settings

    In most services, two-factor authentication is found in the Security section of the account settings. Google account: Manage your Google Account > Security > 2-Step Verification. Microsoft account: two-step verification or the advanced security options in the Security section of your account page. On company accounts, your IT administrator may have made this setting mandatory.

    Diagram: signing in requires both the password and the second verification step : Enlarge
  2. Choose the verification method

    If you can, choose an authenticator app (such as Google Authenticator or Microsoft Authenticator) or a security key / passkey; these are more secure than SMS. With an authenticator app, scan the QR code on the screen with your phone; the app generates a 6-digit code that changes every 30 seconds. Enter this code on the account page to confirm the setup.

    Phone drawing: a 6-digit code and the remaining time in an authenticator app : Enlarge
  3. Store your recovery codes

    Print the backup / recovery codes you are given during setup, or store them in your password manager. If you lose your phone, you can use these codes to get into your account. If possible, add a second verification method as well (a backup phone number or a second key).

    Comparison: security levels of SMS code, authenticator app, approval by notification and security key : Enlarge

App passwords in email programs

After you turn on two-factor authentication, some older email programs or devices may be unable to sign in because they cannot ask for the second step. For this situation, some services offer a special app password created in the account settings. If possible, use a program that supports modern sign-in; use an app password only when necessary, and only in that program.

Things to watch out for

  • Never give your verification code to anyone who asks for it by phone or email; genuine organisations do not ask for your code.
  • Do not approve a sign-in notification that arrives when you are not expecting one; someone may be trying to sign in with your password, so change your password.
  • Before changing phones, move the accounts in your authenticator app to the new phone.
  • If you manage a website, turn on two-factor authentication for your hosting panel, domain account and admin panel too. For the website side, see the Login and session security guide.

Frequently asked questions

Is verification by SMS secure?

It is far better than having nothing at all; however, SMS can be intercepted by methods such as SIM swapping. If you can, prefer an authenticator app or a security key.

I have lost my phone; how do I get into my account?

You can sign in with your recovery codes or with the backup method you added. If you have neither, you will need to follow the service's account recovery process, which can take a long time.

What is a passkey?

It is a method that lets you sign in with the fingerprint, face recognition or screen lock on your device instead of a password. It is resistant to phishing; on services that support it, you can add one in the security settings.

BYK Yazılım Support Team
This guide is written and regularly reviewed by the BYK Yazılım support team. Last updated: 4 October 2026.

Related guides

Let us review the security of your software together

BYK Yazılım supports the websites and software it develops with updates and security. Contact us with your questions.

Contact us Our corporate website service