Business Tech & Tools
What is two-factor authentication, and is text-message verification good enough?
The short answer
Two-factor authentication asks for two different kinds of proof before an account lets you in. Usually that means something you know, such as a password, plus something you have, such as a phone, authenticator app, passkey, or physical security key.
A texted code is much better than a password alone when it is the only second factor offered. For the accounts that could unlock your business, prefer a passkey or security key, then an authenticator app, with text messages as a fallback rather than your first choice.
Understand what the second factor changes
If a scammer steals your password, password-only protection lets her try it immediately. A second factor creates another barrier. It does not make an account impossible to steal, but it can stop a stolen password from being enough.
NIST explains that multifactor authentication combines two or more types of evidence and says passwords alone are not effective protection for sensitive business assets. Its small-business MFA overview gives a plain-language explanation.
The crucial word is different. Two passwords are not two factors. A password and a security question are still two things you know. A password plus a device-held passkey, app code, or security key uses another kind of proof.
Choose the strongest practical option offered
| Option | Good use | Main caution |
|---|---|---|
| Passkey | Strong default when the service and your devices support it | Plan how you will recover or use a second device |
| Physical security key | Excellent for email, password manager, domain, and administrator accounts | Keep a registered spare in a protected place |
| Authenticator app code | Strong, widely available improvement over texts | A convincing fake site can still ask you to type the code |
| Approval prompt | Convenient when it shows useful sign-in details | Never approve a prompt you did not initiate |
| Text-message code | Use when it is the only MFA choice | Phone-number theft, message interception, and phishing can weaken it |
| Email code | Better only if the email account itself is strongly protected | It may fail as a separate barrier when email resets the same account |
CISA recommends requiring MFA and says it reduces the risk of account compromise. Start with the current options in its small-business MFA guidance.
Protect these accounts first
Turn it on today for your primary email, password manager, bank, payment processor, cloud storage, website administrator, domain registrar, social accounts, advertising accounts, and government portals.
Your email deserves first place because it often receives password-reset links. Your password manager follows because it holds the keys to everything else. The domain registrar matters because someone who controls your domain may be able to redirect your website or email.
Set up recovery while you are calm
When you enable MFA:
- Register the strongest method you can use reliably.
- Add a second method or spare key if the provider allows it.
- Save recovery codes outside the account they recover.
- Label the codes with the service and date, without adding the password.
- Test a sign-in from another device before signing out everywhere.
- Review old phone numbers, devices, and app approvals.
Do not photograph recovery codes and leave the picture in the same cloud account. A printed copy in a secure location or an appropriately protected separate record may be safer, depending on your situation.
If text messages are your only choice
Turn them on. Then protect the mobile account with a strong account password and any carrier lock or number-transfer PIN available. Remove outdated phone numbers from business accounts. Be suspicious of a sudden loss of cellular service, especially if login alerts arrive at the same time.
Never read a code to a caller who says she is “verifying your account.” Do not enter a code after following an unexpected link. Open the service from your saved bookmark or type the known address yourself.
Once a stronger method becomes available, upgrade the accounts where a takeover would hurt most. Security should be a ladder you climb, not a test you either pass or fail.
Sources and further reading
A free next step
You don't have to build this alone
Bring your questions, share what you're working on, and meet other women building businesses from home. It is free to join.
Related Questions
- Which cybersecurity basics should a one-person business put in place first?
- Do I need a password manager, and how should I create and manage strong business passwords?
- How do I recognize a phishing email before I click anything?
- What should I do immediately after clicking a phishing link or entering my password on a suspicious site?
