The Step-By-Step Way I Set Up Two-Factor Authentication for Clients

Apr 10, 2026By Jay Kells
Jay Kells

I get asked "how do I actually turn this on?" almost every week, so here's the honest walkthrough I'd give you if we were sat at your kitchen table with your phone in hand.

Why I'm Writing This as an Actual Tutorial


I've written before about why I treat two factor authentication as non-negotiable, and I still stand by every word of that one. But knowing you should do something and knowing how to actually do it are two very different things, and I don't think enough people bridge that gap for their clients. This post skips the persuading and gets straight to the clicking. Grab your phone, get comfortable, and let's go through it properly, one account at a time.


Setting Up 2FA on Your Email Account


Your email is the master key to almost everything else you own online, so it's the first account I secure for every client I work with. In Gmail, go to your Google Account, select Security, then look for 2-Step Verification and follow the prompts. It'll ask for your phone number first, then offer you the option to switch to an authenticator app, which I always recommend over text messages since texts can be intercepted. Outlook works almost the same way: Account, Security, Advanced security options, then Two-step verification. The whole thing takes about three minutes and you only have to do it once.


Setting Up 2FA on Your Banking App


Most UK banking apps have this built in already and switch it on automatically the moment you install them, which is one of the few times I'll happily say the bank knows best. If yours doesn't, open the app, head to Settings or Security, and look for anything called two factor, two step, or biometric login. Turn on Face ID or fingerprint login too if it's offered, it's another layer that costs you nothing and takes half a second each time you log in.


Setting Up 2FA on Social Media


Facebook, Instagram, and X all bury this setting in slightly different places, but the route is roughly the same: Settings, then Security and Login (or Privacy and Security), then Two-Factor Authentication. Pick the authenticator app option where you can, it's more reliable than SMS and doesn't rely on you having signal. I switched every one of my own accounts over years ago and honestly forgot it was even switched on until a login attempt from somewhere I'd never been got blocked without me lifting a finger.

Hand filing a labelled binder of backup codes on a shelf, representing the printed backup codes worth keeping safe in case you lose your phone


What to Do If You Lose Your Phone


This is the bit people worry about most, and fair enough. Before you switch anything on, write down or print the backup codes every service gives you during setup and keep them somewhere safe, not in your phone's notes app. I keep mine in NordPass, the password manager I use and recommend to every client, since it works even if my phone is at the bottom of the Mersey. If you do lose your phone, most services let you verify a new device through your email or by answering a security question, so having that email account locked down properly matters more here than anywhere else.


If any of this feels fiddly the first time, that's completely normal, and I'd rather you found it fiddly for five minutes than found out the hard way why it matters. The National Cyber Security Centre backs up everything I've said here too, if you fancy the official version alongside mine. For a proper hand held walkthrough of everything on your accounts, my digital safety check-up is a good place to start, and I've put together a full safety toolkit with the password manager and VPN I actually use myself. If you'd rather just ask me directly, get in touch and I'll talk you through it.