CoverScore
Guide · Data & PrivacyFree — a $58 hardware key is the only optional purchase · do it yourself

Turn on multi-factor authentication where it matters most

MFA blocks the overwhelming majority of account-takeover attempts — but only the version that isn't defeated by the attacks that actually happened in 2022 and 2023, set up with a real recovery plan in the same sitting. Here is the honest sequence: which accounts first, why the “financial second, carrier third, password manager fourth” order you've read elsewhere isn't an official ranking from anyone, and the two-minute step almost everyone skips that leaves people locked out for weeks.

Total time
~45–90 minutes for your top 5–8 accounts; ongoing after that as passkeys roll out
Cost
Free — a $58 hardware key is the only optional purchase
Difficulty
Fast for the free vendor toggles themselves — the real friction is deciding your short list and storing recovery codes somewhere safe, not the button-clicking.
Last verified
August 2026
Why bother

MFA blocks the overwhelming majority of account-takeover attempts — turned on in the right order, on the right accounts.

Microsoft's own telemetry found MFA cut account-compromise risk by 99.22% — and still cut it 98.56% even when the password had already leaked. That's real and measured, and it comes from commercial/organizational Azure AD accounts specifically, not a consumer-account study — a distinction this guide won't blur.

Meyer et al. (Microsoft), arXiv:2305.00945, 2023

A peer-reviewed study of the top 500 websites found 89.1% reset a forgotten password through email alone. That's the actual evidence behind “secure email first” — the one link in the popular priority-order chain any named authority actually backs.

Li, Wang & Sun, IEEE INFOCOM 2018

9% of Americans 16+ have identity theft happen to them in a given year, and 22% — 1 in 5 — have had it happen at least once in their life. MFA is the single highest-leverage move against the account-takeover slice of that.

BJS, Victims of Identity Theft, 2021 (pub. 2023)
The numbers

What's actually measured — and what isn't.

mitigation
−99.2%

Enabling MFA reduced account-compromise risk by 99.22% — and by 98.56% even for accounts whose passwords had already leaked.

Azure AD accounts flagged with suspicious activity (quasi-experimental) · study window (2023)
identity theft · gradient ladder
9% per year / 22% lifetime

9% of Americans 16+ experience identity theft each year (23.9M people); 22% — 1 in 5 — have experienced it in their lifetime. The peak age band is 50–64, not seniors.

16-17
1.4
18-24
7
25-34
8.9
35-49
9.9
50-64
10.9
65+
8.6
65+ is the terminal band; nothing finer published.
US residents 16+, NCVS Identity Theft Supplement · prior 12 months (2021)
breach
12% per year

12% of Americans 16+ received at least one data-breach notification in a single year — the only true per-person government probability.

US residents 16+ (~263M), household survey · prior 12 months (2021)
The sequence

9 steps, in this order.

Order matters — early steps prevent the later ones from failing or being wasted effort.
01

Pick your short list — 5 to 8 accounts, not everything

Decide the accounts where compromise would be catastrophic before touching any settings. Nobody with a full digital life turns on MFA everywhere in one sitting, and pretending otherwise is why most exhaustive account-by-account guides get abandoned after the third one. Email, your password manager, your bank, and your phone carrier account belong on this list before anything else does.

What belongs on the short list
  • Your primary email — the account most other passwords reset through
  • Your password manager, if you use one
  • Bank, brokerage, and your primary credit card
  • Your phone carrier account (needed if anything above will use SMS as a factor)
10 minFreeonce
02

Lock your phone carrier account if anything will use SMS

SMS-based MFA is only as strong as control of the phone number, and control of the phone number is only as strong as the carrier account's own defenses. Every major carrier's SIM-swap protection is opt-in and off by default, so if any account on your short list will lean on a text message, lock the carrier account first or in the same sitting — not after.

Per carrier
  • AT&T — myAT&T app → Services → Mobile Security → Wireless Account Lock, plus a separate Extra Security Passcode at att.com/acctmgmt (wireless-only; not available on internet-bundled or business accounts)
  • T-Mobile — T-Life app → Security → SIM Protection, and separately Port Out Protection under Manage add-ons per line — two different, easily confused features; some accounts have reported Port Out Protection getting stuck on even after toggling it off
  • Verizon — Account settings → Security settings → SIM Protection and Number Lock; the strongest option, Port Freeze, requires calling *611, not a self-service toggle
  • A carrier PIN raises the bar against remote, automated SIM-swap attempts significantly — it does not stop a determined attacker who talks a retail employee into bypassing it, which is a documented, not theoretical, failure mode
5–10 min per carrierFreeonce — re-check after any plan or line change
03

Secure your primary email — and store the recovery method in the same sitting

This is the highest-leverage step on the list: a peer-reviewed study of the top 500 websites found 89% reset a password through email alone. Turning on MFA is two actions, not one — the setup flow bundles a primary method (an app, a passkey, or a key) with a recovery method (backup codes, a recovery key, a recovery contact), and the recovery step is the one people skip and later get locked out over.

What to actually do
  • Google — myaccount.google.com → Security → 2-Step Verification; store the 8-digit backup codes somewhere other than the phone (not downloadable if you're enrolled in Advanced Protection)
  • Apple — Settings → [Your Name] → Sign-in & Security → Recovery Key; Apple's own warning is blunt — lose it and you're locked out permanently — never store it in Apple Passwords, iCloud Photos, Notes, or iCloud Drive
  • Microsoft — account.microsoft.com → Security → Advanced security options; Authenticator supports both number-matching push and passkey registration
  • Real recovery waits, from documented cases, not marketing copy: Apple Community threads report 6-, 13-, and 26-day waits; Google states only “a few hours or a number of days” with no fixed number — the delay is a deliberate feature, giving the real owner time to notice and block an attacker
10–15 min setup, plus storing recovery codesFreeonce; re-verify recovery codes are findable about annually and after any phone replacement
04

Secure your password manager with its own MFA

A password manager without its own MFA becomes a second master key holding every other account's password — do this at the same time as email, not after. Whether to also store your codes inside the same vault is a genuine trade-off, not a settled rule: 1Password argues the single-device threat model makes separate storage mostly theoretical, but the more conservative choice for your single highest-value accounts is a separate app or a physical key.

Before you rely on an authenticator app
  • Confirm it supports encrypted backup or export before you need it — Authy's desktop app shut down in March 2024 with no export feature, and switchers had to disable and re-enroll 2FA on every account individually
  • Google Authenticator added cloud sync in 2023, but reporting at the time found the synced codes weren't end-to-end encrypted — verify current status before assuming your codes are protected in transit
5 min if you already use oneFreeonce — treat it like step 3 in importance
05

Secure financial accounts with whatever the strongest option actually is

Bank MFA offerings are inconsistent and mostly not your choice. Some major banks lean on SMS or a voice call as the only second factor; a smaller number support passkeys. Federal guidance to banks is risk-based, not a specific-method mandate — if your bank only offers SMS, you can't fix that from your end, so the honest move is putting more weight on the accounts you actually control: the carrier account and the email that resets the bank password.

The honest state of things
  • Verify your own bank's current options on its own site — one industry tracker lists Chase, Wells Fargo, Capital One, and Truist among banks supporting passkeys, and Bank of America, Fidelity, Citibank, and Citizens among those that don't, as of the sources checked; this changes without much notice, in both directions
  • Banks have documented removing security features, not just adding them — Bank of America previously offered one-time passcodes at payee add/change and removed them, flagged publicly by industry analysts as a security regression
5–10 min per institutionFreeonce, recheck yearly — banks add and remove features
06

Secure the device-ecosystem account behind your phone and computer

Your Apple ID, Google Account, or Microsoft account is often the same account as your email, which collapses this step into step 3. Handle it separately only when your phone or computer's ecosystem account runs on a different email provider than the one you already secured.

5–10 min, if not already covered by step 3Freeonce
07

Social media and messaging accounts

Lower stakes than the accounts above for most people, but the fastest to be weaponized against your contacts once compromised — a hacked social account gets used to scam the people who trust you. Check passkey support per platform rather than assuming; Meta announced Facebook passkeys in June 2025 but launched mobile-only at first, with desktop and Messenger support following later.

5 min eachFreeonce, per account
08

Everything else — work through it opportunistically

Shopping, streaming, and gaming accounts are the lowest priority here — this guide gives you explicit permission to stop at step 7 rather than treating every account you've ever signed up for as an obligation. A running checklist like the 2FA directory (2fa.directory) works fine for whatever you eventually get to.

ongoing, a few minutes per accountFreeas needed
09

Upgrade to a passkey or hardware key as it becomes available

Where a top-priority account newly offers a passkey or a hardware security key, upgrade from an app code or SMS to it. Passkey support is still rolling out per-service through 2026, so this is maintenance, not a task you finish once. A hardware key (about $58 for a YubiKey 5 NFC) is the strongest available tier where a service supports it — buy two and store the second one separately, since losing your only key is a lockout failure mode of its own.

The one tier that resists real-time phishing
  • FIDO2 security keys and passkeys are structurally immune to a real-time phishing proxy, because the cryptographic challenge is bound to the real site's domain and can't be relayed — TOTP codes and even number-matching push approvals can still be stolen this way
5 min per account, whenever offeredFreeongoing — not a one-time step
Learn from everyone else's mistakes

Where this actually goes wrong

  • You turn on MFA for the primary method but skip storing the recovery codes — losing your phone later means Apple's undefined “several days or more” (real cases: 6 to 26 days) or Google's “hours to days,” not a quick fix.
  • You enable SMS as a factor on your email or bank before locking the carrier account — the new “second factor” inherits an unlocked front door, since SMS is only as strong as control of the phone number.
  • You accept a bare approve/deny push prompt instead of number-matching push — this is the exact mechanism that let attackers into Uber (2022) via prompt-bombing and MGM Resorts (2023) via a fooled help desk.
  • You assume “I have MFA, so I can't be phished” — a real-time phishing proxy relays your login and steals the resulting session after you approve a normal code or push, and only phishing-resistant methods (security keys, passkeys) are immune to that.
  • You switch phones without checking whether your authenticator app supports export — Authy's 2024 shutdown left switchers disabling and re-enrolling 2FA on every account individually, one at a time.
Do it with your own AI

You already pay for an assistant that can do the drafting.

Paste one of these prompts in, fill in your details, and it will draft the checklist or the letter for you — the guardrails below each prompt are built from the failure modes AI assistants specifically hit on this topic.

We don't see your details and we're not in the loop. This is genuinely yours to run.

Paste into your assistant
Help me build a personal priority order for turning on MFA across my accounts, starting from the accounts that matter most.

MY SITUATION
- Which of these do I already use: a password manager [YES/NO], an authenticator app [YES/NO], a hardware security key [YES/NO]
- Will any of my top accounts rely on SMS as a factor: [YES/NO]

WHAT I NEED
1. A numbered list covering: my short list of 5–8 highest-stakes accounts, locking my carrier account if I'll use SMS anywhere, securing email with a stored recovery method, securing my password manager, financial accounts, device-ecosystem accounts, social accounts, and everything else.
2. Put the steps in dependency order — which ones have to happen before others, not just importance order.
3. Tell me plainly which parts of this ordering are official guidance and which are reasoned prioritization with no named authority behind them.

RULES
- Do not attribute the “email → financial → carrier → password manager” order to CISA, NIST, or the FTC — only “secure email first” has a named source (EFF's Surveillance Self-Defense guide); say so explicitly.
- Do not tell me a specific bank, retailer, or social platform currently supports passkeys or a specific MFA method from memory — tell me to check that service's own current security page, and note that rollouts are often partial even after a public announcement.
- Do not cite a specific percentage for how much MFA reduces account compromise without naming the source, year, and what population it measured. If I mention “99.9%,” tell me that figure traces to an unsourced 2019 Microsoft marketing blog post, not the peer-reviewed studies.

Check what it produces before sending — verify any statute, phone number, or URL it gives you.

Questions

The things people actually ask.

Yes, and a lot of security content overstates the case against it. Google's own research found SMS-based recovery still blocks 100% of automated bot attacks and 96% of bulk phishing — that's real, measured protection. It's the weakest available tier, not a non-functional one, but it's still the wrong choice for accounts where a SIM swap or targeted phishing would be catastrophic.

What MFA doesn't do
  • It doesn't make you unphishable. A real-time phishing proxy relays a normal login and steals the resulting session after you approve a code or even a number-matching push — only FIDO2 security keys and passkeys structurally resist this, because the cryptographic challenge is bound to the real site's domain.
  • It doesn't fix a bank that only offers SMS. Federal guidance to banks is risk-based, not a specific-method mandate, and gives you no lever to demand a stronger option — use what's offered, and put more weight on the accounts you actually control.
  • No agency has published the “email → financial → carrier → password manager” priority order as an official ranking. Only “secure email first” has a named source behind it; the rest of this guide's sequence is reasoned prioritization, stated as such, not a citable framework.
  • It doesn't survive a lost phone by itself. Recovery codes, a recovery key, or a recovery contact have to be set up before you need them — Apple and Google both describe undefined, sometimes multi-week, recovery timelines with no fixed guarantee.
  • The widely repeated “99.9% of attacks blocked” figure has no published methodology behind it — it traces to a 2019 Microsoft marketing blog post, not either of the two studies with real, scoped numbers this guide actually cites.
Sources · last verified August 2026
Source · Li, Wang & Sun, IEEE INFOCOM — Email as a Master Key: Analyzing Account Recovery in the Wild (2018)
tier A
Source · FFIEC / Federal Reserve — Authentication and Access to Financial Institution Services and Systems (2021)
tier A
Source · NIST — SP 800-63B Digital Identity Guidelines — SMS OTP downgraded to a restricted authenticator
tier A
Source · Krebs on Security — Hanging Up on Mobile in the Name of Security (2018)
tier B
Source · FIDO Alliance / Sapio Research — The State of Passkeys: Global Consumer and Workforce Report (2026)
tier C
Source · An officially ranked “which accounts first” MFA priority framework from CISA, NIST, or the FTC
no data