Two-factor authentication adds a second verification step, such as a code or security key, after a password.

Two different proofs

2FA combines a password with a second factor, such as an authenticator code, hardware key, or approved device. Stealing the password alone should not be enough to sign in.

Factor choice changes protection

One-time codes are stronger than passwords but can be phished. Security keys resist many fake-login attacks, while recovery procedures determine what happens when a device is lost.