Which Accounts Need 2FA First? Start With Email
7 min read
Almost everybody already knows two-factor authentication should be switched on. What stops them is rarely disagreement, it is not knowing where to begin. A company runs twenty-odd services, each one needs configuring, each one needs explaining to colleagues, and just thinking about it produces "let's do it another day" for the next two years. You do not actually need all of them. One account outranks every other account you own, and switching that one on removes more risk than the next ten combined. This covers the order, what each of the three methods costs you, and the backup code problem every tutorial skips.
1. Email goes first, for one reason
Two-factor authentication means that signing in takes something beyond the password. That something might be a code on your phone, or a small key you plug into the computer. The password is what you know, the second factor is what you hold, and losing both at once is far less likely than a password leaking on its own.
The account to start with is the company mailbox, or whichever address you used to register everything else. Not because the messages are sensitive, but because it is the spare key to every other account. Think about what you do when you forget a password on some website: click "forgot password", then go and read your email. Every reset flow in existence ends up back in that mailbox.
So somebody holding your mailbox needs none of your other passwords. They can reset them one by one. That is also why attackers find mailboxes so interesting. A common first move after getting in is not reading anything, it is creating a forwarding rule that quietly copies every notification elsewhere. Your mail keeps arriving normally and nothing looks wrong.
The switch itself lives in the account security settings. On a Google account, turning on 2-Step Verification is its own option, and once it is set the same page shows which methods are currently attached. Microsoft, Apple and most cloud services put it in much the same place, under "security" or "how you sign in".
2. Working out the rest of the order
With email done, two tests decide everything else: whether losing this account drags other accounts down with it, and whether it can reach money or customer data directly. Apply those two and most companies end up with a list like this one.
| Order | Account | What happens without it |
|---|---|---|
| First | Company and work email | Every other service can be reset, so they all go at once |
| Second | Domain registrar, hosting and cloud panels | A transferred domain stops the site and the mail together, and recovery runs into weeks |
| Third | Online banking and payment back ends | Money moves directly, and most banks mandate it anyway |
| Fourth | The password manager master account | Every password ends up in there, so that door has to be the strongest |
| Fifth | Website admin and internal systems | Customer data lives here, so it is other people's interests at stake |
| Last | Social platforms and other subscriptions | Still worth doing, but the blast radius is smaller and it can be scheduled |
The table does not have to be finished in one sitting. In practice the first three cover most of what would genuinely stop the company. Put the rest in a fixed slot each month, two or three at a time, and the list clears inside half a year.
3. SMS, an authenticator app, or a hardware key
Switching it on presents a choice: receive the code by text message, generate it in an authenticator app, or plug in a physical key. All three count as two-factor authentication, all three differ in how much they protect and how much they annoy people, and none of them is right for every situation.
Text messages are the easiest to adopt. Nothing to install, and colleagues who dislike computers can manage it. The weakness is that the phone number itself can be taken. Somebody presents forged documents to get a replacement SIM, or talks a support agent into porting the number onto their own card, and your codes now arrive on their handset. The NIST digital identity guidelines therefore treat codes sent over the telephone network as a restricted method, and ask services to weigh signals such as a recent SIM change or number port first.
An authenticator app is a program on the phone showing a number that changes every thirty seconds. It never touches the telephone network, so the replacement SIM trick does not apply, and it produces codes with no connectivity at all. For most small companies, stopping at this layer is good enough.
A hardware key is a small object you plug in or tap against the phone. It blocks one thing the other two do not: a convincing fake sign-in page. The key checks which address you are actually on and refuses to act if the address is wrong, so there is no code for you to type into a phishing site. The cost is money, and buying two of them, because you want a spare.
4. Save the backup codes now
This is the most practical section here. Backup codes are the one-time codes a service hands you as you switch two-factor authentication on, so that you can still get in when the phone is not with you. Most people reach this step, press "remind me later", and there is no later. The day you need them tends to be the day you have least time to spare.
On a Google account, backup codes come ten at a time, each usable once, and generating a fresh set invalidates every previous code. Other services work along much the same lines. Note what regenerating does: people assume it means ten more codes, when it actually means the sheet already printed is now waste paper.
Where the backup codes go
- Print them and file them with the important documents. Wherever the company seals and the registration papers live. It is the least sophisticated option and the only one that survives every device you own failing.
- Store them in the password manager, on the entry for that account. Convenient, and visible during a handover. But if the password manager master account is also secured by the same phone, this copy cannot rescue that situation.
- Give a copy to a second person. Important company accounts can have two holders, with either one used only after telling the other. It also solves the problem of nobody being able to get in while the owner is abroad.
- Do not keep the only copy in the phone's photo album. Lose the phone and you generally lose access to the album too, which is exactly the moment the codes were for.
Keep at least two copies and do not store them in the same place. The test is easy: picture the phone going into a river right now and not coming back. Can you still reach both copies? If you can answer that, you are covered.
5. Lost the phone and cannot find the backup codes
This is the most common situation and the least often written about. The short answer is that it is not hopeless, but it will drag on and it may not work. Which is why the previous section is worth doing today.
Most services run an account recovery process built around proving you are the owner. It will ask roughly when the account was created, which devices you normally use, who you recently corresponded with, or it will require you to start from a device and location you have signed in from before. The closer your answers, the better the odds. It usually takes several days, and some services impose a waiting period, which exists precisely to make impersonation harder.
A few things push the success rate down sharply: attempting it from a brand new device on an unfamiliar network, having no recovery contact details on the account at all, and panicking into repeated attempts that trigger a lockout. If any device that once signed in to that account is still signed in, leave it alone. Starting recovery from that machine has by far the best chance.
6. Rolling it out to colleagues
Technically this takes minutes. The hard part is getting a dozen people to actually do it. What works in practice is not announcing all of it at once but following the table in the second section from the top down, one layer a month. People cooperate far better when they can see where it ends.
How you put it matters too. "New policy" tends not to land. "This protects you, because if somebody sends mail as you, you are the first person suspected" has a better chance. Better still is a demonstration: walk through a password reset in a meeting so everyone sees that holding the mailbox is enough to reset other accounts. Most people understand why email ranks first on the spot.
Then keep a record. Which accounts are covered, by which method, who holds the backup codes, whose phone it is bound to. That record does nothing on an ordinary day. It earns its keep when somebody joins or leaves, and without it you are reduced to testing accounts one at a time.
Two-factor authentication does not have to go on everywhere at once. It needs an order. Email first, because every other service sends its reset there. Then the domain, the hosting, and anything touching money. An authenticator app is a good enough starting method, with hardware keys reserved for the accounts handling payments and large volumes of customer data. Then keep two copies of the backup codes in two different places. That is the one thing that saves you from spending days proving who you are after losing a phone.
Common questions
- What is two-factor authentication, and how does it differ from a password?
- It adds a second step beyond the password, which might be a code sent to your phone, six digits from an authenticator app, or a physical key. The password is what you know and the second factor is what you hold. Passwords leak, get guessed, or get talked out of you, whereas the attacker usually does not have the handset in your pocket. So even when the password does get out, the account still has something in the way.
- Is receiving codes by SMS good enough?
- It is, and it beats not having it on at all. What to know is that the weakness sits in the phone number: somebody can obtain a replacement SIM with forged documents or port the number to their own card, and your codes arrive with them. So for email, the domain and anything touching money, move to an authenticator app, which never touches the telephone network and works with no signal. For colleagues who struggle with technology, start on SMS and move them later.
- I lost my phone. Can I still get into an account with 2FA?
- If you saved backup codes, yes: one code replaces the usual second step. Without them you go through account recovery, where the service asks you to prove ownership, which typically takes several days and is not guaranteed to succeed. If any device that once signed in to that account is still signed in, do not touch it. Starting the recovery request from that machine gives you the best odds.