Yes — you can turn on 2-Step Verification for a Google account in under five minutes, and the strongest setup uses an authenticator app or a passkey rather than SMS. Google made 2-Step Verification the default state for 150 million accounts by the end of 2021, per the company's own security blog, but default SMS prompts are not the strongest option, and this guide shows the better path.
KAJ News publishes information, not security services; these steps match Google's documented flows for Google Account interfaces as of 2024, and menus can shift with updates.
Why is an authenticator app or passkey better than SMS?
SMS codes travel through the phone network, and that network has a documented weakness: attackers can redirect your messages through SIM-swap fraud, in which a carrier moves your number to a device they control. The U.S. Cybersecurity and Infrastructure Security Agency's guidance on multi-factor authentication, updated in 2024, recommends phishing-resistant methods — authenticator apps, security keys, and passkeys — over SMS wherever the service offers them.
An authenticator app generates codes on your device only. A passkey goes further: it binds the login to the exact site, so a phishing page that imitates the sign-in screen cannot use it.
Which method should you pick?
The honest comparison is short.
| Method | Strengths | Weaknesses |
|---|---|---|
| Passkey or hardware security key | Phishing-resistant; recommended by CISA's 2024 MFA guidance | Needs a compatible device or a key you must not lose |
| Authenticator app | Codes stay on-device; survives SIM swap | Losing the phone locks you out unless you saved backup codes |
| SMS code | Works on any phone; better than nothing | Vulnerable to SIM-swap and message interception |
Google Accounts support all three. If your device supports passkeys, start there and add an authenticator app as a backup method.
How do you turn on 2-Step Verification?
These steps match the Google Account web interface as documented in Google Account Help, current as of 2024. Android and iOS apps follow the same screens.
- Open a browser and go to myaccount.google.com. Sign in with the account you are protecting. You'll see your account dashboard.
- Select Security from the left-hand menu. You'll see a security status page with a list of settings.
- Scroll to How you sign in to Google and select 2-Step Verification. You'll be asked to confirm your password. That's normal — Google re-verifies before security changes.
- Click Get Started and follow the prompts to confirm a phone number. Google sends a test code by SMS. This step is mandatory even if you plan to skip SMS later; it becomes the fallback method.
- After the phone check, you'll see the 2-Step Verification settings page. This is the control panel — everything below happens here.
How do you add an authenticator app?
Use Google Authenticator, available free on Android and iOS, or any time-based app such as Aegis or Raivo. The enrollment flow is the documented one as of version 3.x of Google Authenticator on Android.
- On the 2-Step Verification page, select Authenticator app under Add more second steps to verify it's you.
- Choose your phone type. Google shows a QR code. That's the enrollment screen.
- Open the authenticator app, tap the plus sign, and select Scan a QR code. Point the camera at the screen.
- The app displays a six-digit code for your Google account. Type it into the verification field on the page. Google confirms the app is linked.
How do you add a passkey?
Passkeys live in the same security area, and enrollment takes one screen.
- On the Security page, select Passkeys. You'll see a list of passkeys already created for your devices.
- Select Create a passkey. Follow the device prompt — fingerprint, face, or screen lock on Android and iOS, or Touch ID on a Mac. That's the whole enrollment.
- Sign out and sign back in once. You'll be offered the passkey instead of a password. Confirm it works before you rely on it.
What are backup codes and why do you need them?
Backup codes are one-time codes printed or saved at enrollment, and they are the difference between an inconvenience and a lockout. On the 2-Step Verification page, select Backup codes and Google displays ten eight-digit codes. Save them somewhere offline — printed paper in a drawer, not a screenshot on the phone the codes exist to back up. Each code works once.
Then check the recovery phone and recovery email on the Security page. Both are verified channels Google uses when you lose every other method, and stale recovery details are the most common reason people get locked out after enabling 2-Step Verification.
What this setup establishes: codes that never transit the phone network, a phishing-resistant sign-in option, and an offline path back in. What it does not cover: other accounts. Repeat the same pattern — passkey or authenticator app first, SMS only as fallback — on every service that holds money or personal data, starting with email, because email resets everything else.
For more context, read Edison Aerospace to attend UAS Summit and Expo.
