Turn on multi-factor authentication where it matters most
MFA blocks the overwhelming majority of account-takeover attempts — but only the version that isn't defeated by the attacks that actually happened in 2022 and 2023, set up with a real recovery plan in the same sitting. Here is the honest sequence: which accounts first, why the “financial second, carrier third, password manager fourth” order you've read elsewhere isn't an official ranking from anyone, and the two-minute step almost everyone skips that leaves people locked out for weeks.
MFA blocks the overwhelming majority of account-takeover attempts — turned on in the right order, on the right accounts.
Microsoft's own telemetry found MFA cut account-compromise risk by 99.22% — and still cut it 98.56% even when the password had already leaked. That's real and measured, and it comes from commercial/organizational Azure AD accounts specifically, not a consumer-account study — a distinction this guide won't blur.
Meyer et al. (Microsoft), arXiv:2305.00945, 2023A peer-reviewed study of the top 500 websites found 89.1% reset a forgotten password through email alone. That's the actual evidence behind “secure email first” — the one link in the popular priority-order chain any named authority actually backs.
Li, Wang & Sun, IEEE INFOCOM 20189% of Americans 16+ have identity theft happen to them in a given year, and 22% — 1 in 5 — have had it happen at least once in their life. MFA is the single highest-leverage move against the account-takeover slice of that.
BJS, Victims of Identity Theft, 2021 (pub. 2023)What's actually measured — and what isn't.
Enabling MFA reduced account-compromise risk by 99.22% — and by 98.56% even for accounts whose passwords had already leaked.
9% of Americans 16+ experience identity theft each year (23.9M people); 22% — 1 in 5 — have experienced it in their lifetime. The peak age band is 50–64, not seniors.
12% of Americans 16+ received at least one data-breach notification in a single year — the only true per-person government probability.
9 steps, in this order.
Pick your short list — 5 to 8 accounts, not everything
Decide the accounts where compromise would be catastrophic before touching any settings. Nobody with a full digital life turns on MFA everywhere in one sitting, and pretending otherwise is why most exhaustive account-by-account guides get abandoned after the third one. Email, your password manager, your bank, and your phone carrier account belong on this list before anything else does.
- Your primary email — the account most other passwords reset through
- Your password manager, if you use one
- Bank, brokerage, and your primary credit card
- Your phone carrier account (needed if anything above will use SMS as a factor)
Lock your phone carrier account if anything will use SMS
SMS-based MFA is only as strong as control of the phone number, and control of the phone number is only as strong as the carrier account's own defenses. Every major carrier's SIM-swap protection is opt-in and off by default, so if any account on your short list will lean on a text message, lock the carrier account first or in the same sitting — not after.
- AT&T — myAT&T app → Services → Mobile Security → Wireless Account Lock, plus a separate Extra Security Passcode at att.com/acctmgmt (wireless-only; not available on internet-bundled or business accounts)
- T-Mobile — T-Life app → Security → SIM Protection, and separately Port Out Protection under Manage add-ons per line — two different, easily confused features; some accounts have reported Port Out Protection getting stuck on even after toggling it off
- Verizon — Account settings → Security settings → SIM Protection and Number Lock; the strongest option, Port Freeze, requires calling *611, not a self-service toggle
- A carrier PIN raises the bar against remote, automated SIM-swap attempts significantly — it does not stop a determined attacker who talks a retail employee into bypassing it, which is a documented, not theoretical, failure mode
Secure your primary email — and store the recovery method in the same sitting
This is the highest-leverage step on the list: a peer-reviewed study of the top 500 websites found 89% reset a password through email alone. Turning on MFA is two actions, not one — the setup flow bundles a primary method (an app, a passkey, or a key) with a recovery method (backup codes, a recovery key, a recovery contact), and the recovery step is the one people skip and later get locked out over.
- Google — myaccount.google.com → Security → 2-Step Verification; store the 8-digit backup codes somewhere other than the phone (not downloadable if you're enrolled in Advanced Protection)
- Apple — Settings → [Your Name] → Sign-in & Security → Recovery Key; Apple's own warning is blunt — lose it and you're locked out permanently — never store it in Apple Passwords, iCloud Photos, Notes, or iCloud Drive
- Microsoft — account.microsoft.com → Security → Advanced security options; Authenticator supports both number-matching push and passkey registration
- Real recovery waits, from documented cases, not marketing copy: Apple Community threads report 6-, 13-, and 26-day waits; Google states only “a few hours or a number of days” with no fixed number — the delay is a deliberate feature, giving the real owner time to notice and block an attacker
Secure your password manager with its own MFA
A password manager without its own MFA becomes a second master key holding every other account's password — do this at the same time as email, not after. Whether to also store your codes inside the same vault is a genuine trade-off, not a settled rule: 1Password argues the single-device threat model makes separate storage mostly theoretical, but the more conservative choice for your single highest-value accounts is a separate app or a physical key.
- Confirm it supports encrypted backup or export before you need it — Authy's desktop app shut down in March 2024 with no export feature, and switchers had to disable and re-enroll 2FA on every account individually
- Google Authenticator added cloud sync in 2023, but reporting at the time found the synced codes weren't end-to-end encrypted — verify current status before assuming your codes are protected in transit
Secure financial accounts with whatever the strongest option actually is
Bank MFA offerings are inconsistent and mostly not your choice. Some major banks lean on SMS or a voice call as the only second factor; a smaller number support passkeys. Federal guidance to banks is risk-based, not a specific-method mandate — if your bank only offers SMS, you can't fix that from your end, so the honest move is putting more weight on the accounts you actually control: the carrier account and the email that resets the bank password.
- Verify your own bank's current options on its own site — one industry tracker lists Chase, Wells Fargo, Capital One, and Truist among banks supporting passkeys, and Bank of America, Fidelity, Citibank, and Citizens among those that don't, as of the sources checked; this changes without much notice, in both directions
- Banks have documented removing security features, not just adding them — Bank of America previously offered one-time passcodes at payee add/change and removed them, flagged publicly by industry analysts as a security regression
Secure the device-ecosystem account behind your phone and computer
Your Apple ID, Google Account, or Microsoft account is often the same account as your email, which collapses this step into step 3. Handle it separately only when your phone or computer's ecosystem account runs on a different email provider than the one you already secured.
Social media and messaging accounts
Lower stakes than the accounts above for most people, but the fastest to be weaponized against your contacts once compromised — a hacked social account gets used to scam the people who trust you. Check passkey support per platform rather than assuming; Meta announced Facebook passkeys in June 2025 but launched mobile-only at first, with desktop and Messenger support following later.
Everything else — work through it opportunistically
Shopping, streaming, and gaming accounts are the lowest priority here — this guide gives you explicit permission to stop at step 7 rather than treating every account you've ever signed up for as an obligation. A running checklist like the 2FA directory (2fa.directory) works fine for whatever you eventually get to.
Upgrade to a passkey or hardware key as it becomes available
Where a top-priority account newly offers a passkey or a hardware security key, upgrade from an app code or SMS to it. Passkey support is still rolling out per-service through 2026, so this is maintenance, not a task you finish once. A hardware key (about $58 for a YubiKey 5 NFC) is the strongest available tier where a service supports it — buy two and store the second one separately, since losing your only key is a lockout failure mode of its own.
- FIDO2 security keys and passkeys are structurally immune to a real-time phishing proxy, because the cryptographic challenge is bound to the real site's domain and can't be relayed — TOTP codes and even number-matching push approvals can still be stolen this way
Where this actually goes wrong
- You turn on MFA for the primary method but skip storing the recovery codes — losing your phone later means Apple's undefined “several days or more” (real cases: 6 to 26 days) or Google's “hours to days,” not a quick fix.
- You enable SMS as a factor on your email or bank before locking the carrier account — the new “second factor” inherits an unlocked front door, since SMS is only as strong as control of the phone number.
- You accept a bare approve/deny push prompt instead of number-matching push — this is the exact mechanism that let attackers into Uber (2022) via prompt-bombing and MGM Resorts (2023) via a fooled help desk.
- You assume “I have MFA, so I can't be phished” — a real-time phishing proxy relays your login and steals the resulting session after you approve a normal code or push, and only phishing-resistant methods (security keys, passkeys) are immune to that.
- You switch phones without checking whether your authenticator app supports export — Authy's 2024 shutdown left switchers disabling and re-enrolling 2FA on every account individually, one at a time.
You already pay for an assistant that can do the drafting.
Paste one of these prompts in, fill in your details, and it will draft the checklist or the letter for you — the guardrails below each prompt are built from the failure modes AI assistants specifically hit on this topic.
We don't see your details and we're not in the loop. This is genuinely yours to run.
Help me build a personal priority order for turning on MFA across my accounts, starting from the accounts that matter most. MY SITUATION - Which of these do I already use: a password manager [YES/NO], an authenticator app [YES/NO], a hardware security key [YES/NO] - Will any of my top accounts rely on SMS as a factor: [YES/NO] WHAT I NEED 1. A numbered list covering: my short list of 5–8 highest-stakes accounts, locking my carrier account if I'll use SMS anywhere, securing email with a stored recovery method, securing my password manager, financial accounts, device-ecosystem accounts, social accounts, and everything else. 2. Put the steps in dependency order — which ones have to happen before others, not just importance order. 3. Tell me plainly which parts of this ordering are official guidance and which are reasoned prioritization with no named authority behind them. RULES - Do not attribute the “email → financial → carrier → password manager” order to CISA, NIST, or the FTC — only “secure email first” has a named source (EFF's Surveillance Self-Defense guide); say so explicitly. - Do not tell me a specific bank, retailer, or social platform currently supports passkeys or a specific MFA method from memory — tell me to check that service's own current security page, and note that rollouts are often partial even after a public announcement. - Do not cite a specific percentage for how much MFA reduces account compromise without naming the source, year, and what population it measured. If I mention “99.9%,” tell me that figure traces to an unsourced 2019 Microsoft marketing blog post, not the peer-reviewed studies.
Check what it produces before sending — verify any statute, phone number, or URL it gives you.
The things people actually ask.
Yes, and a lot of security content overstates the case against it. Google's own research found SMS-based recovery still blocks 100% of automated bot attacks and 96% of bulk phishing — that's real, measured protection. It's the weakest available tier, not a non-functional one, but it's still the wrong choice for accounts where a SIM swap or targeted phishing would be catastrophic.
- It doesn't make you unphishable. A real-time phishing proxy relays a normal login and steals the resulting session after you approve a code or even a number-matching push — only FIDO2 security keys and passkeys structurally resist this, because the cryptographic challenge is bound to the real site's domain.
- It doesn't fix a bank that only offers SMS. Federal guidance to banks is risk-based, not a specific-method mandate, and gives you no lever to demand a stronger option — use what's offered, and put more weight on the accounts you actually control.
- No agency has published the “email → financial → carrier → password manager” priority order as an official ranking. Only “secure email first” has a named source behind it; the rest of this guide's sequence is reasoned prioritization, stated as such, not a citable framework.
- It doesn't survive a lost phone by itself. Recovery codes, a recovery key, or a recovery contact have to be set up before you need them — Apple and Google both describe undefined, sometimes multi-week, recovery timelines with no fixed guarantee.
- The widely repeated “99.9% of attacks blocked” figure has no published methodology behind it — it traces to a 2019 Microsoft marketing blog post, not either of the two studies with real, scoped numbers this guide actually cites.