The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Turn on multi-factor authentication (MFA) for your primary email, financial accounts, and other important accounts wherever it is offered. MFA adds a verification step beyond your password, so a stolen password alone may not be enough to sign in. Prefer a phishing-resistant security key when the service supports one; otherwise, choose an authenticator app if available.
What MFA adds to account security
MFA requires another verification step in addition to a password. That second step can make it harder for someone to access an account using a stolen or guessed password. The Cybersecurity and Infrastructure Security Agency (CISA) explains on its consumer “Turn On MFA” guidance page: “Even if an unauthorized user steals your password, they won’t be able to meet the second step requirement to access your accounts.”
MFA reduces risk; it does not guarantee an account cannot be taken over. Some methods remain vulnerable to phishing or other attacks, so the type of second factor matters.
How to enable MFA
- Start with high-impact accounts. Enable MFA on your primary email, financial accounts, and other accounts you would find difficult to recover or whose compromise could expose other services. CISA encourages using MFA on each account or app that offers it.
- Open the account settings. Sign in to the service and look under account or profile settings for a section named Security, Password and security, or something similar.
- Find the MFA setting. The service may call it “Two Factor Authentication,” “Multifactor Authentication,” or “Two Step Factor Authentication.” Select the option and follow that service’s setup flow. The available methods and exact labels vary by provider.
- Choose the strongest practical method offered. Use a phishing-resistant security key if the service supports it. Otherwise, select an authenticator app if offered; use text or email codes only when stronger choices are unavailable.
- Finish setup and keep recovery guidance accessible. Follow the provider’s instructions for completing enrollment and account recovery. Recovery steps differ by service, so use its current guidance rather than assuming one universal process.
Which MFA method should you choose?
CISA’s small-business guidance recommends phishing-resistant MFA and presents security keys as the strongest option among the methods it discusses. The hierarchy below reflects that guidance, which is written for organizations; it is not a guarantee that every consumer account offers these methods or implements them identically.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Method | What to know | Practical choice |
|---|---|---|
| Phishing-resistant security key | A physical key is CISA’s strongest listed option and is designed to resist phishing. CISA names YubiKey as an example. | Prefer this when the account supports it. Check that the particular service and your devices are compatible before choosing a key. |
| Authenticator app | An app can provide one-time codes or prompts. CISA lists app-generated codes as an alternative to phishing-resistant MFA. | A practical choice when a security key is not available for the account. |
| Number-matching app prompt | Matching a number can help reduce push-fatigue attacks, in which an attacker repeatedly sends prompts hoping the user will approve one. CISA calls number matching an interim mitigation, not as strong as phishing-resistant MFA. | Use it if the account relies on push prompts and offers number matching, while preferring phishing-resistant MFA when possible. |
| Biometrics | CISA notes that biometrics are usually specific to a device and are best used alongside another method. | Use as part of the account’s supported MFA setup, rather than assuming a device biometric alone protects every account. |
| Text or email code | CISA describes text and email codes as the weakest of the options in its comparison. SMS can be exposed to SIM swapping or SS7-related attacks. | Use as a fallback if stronger methods are unavailable; do not treat it as equivalent to a security key or app-based option. |
Risks MFA does not remove
CISA’s October 2022 MFA fact sheet warns that some implementations can still be threatened by phishing, push bombing, SS7 protocol attacks, and SIM swapping. An attacker may target the second factor itself rather than relying only on a stolen password. Unexpected sign-in prompts should not be approved; deny them and investigate through the service’s official account-security process.
- Phishing: Some MFA methods can be tricked through fraudulent sign-in pages or requests.
- Push bombing: Repeated prompts can pressure a user into approving access. Number matching can mitigate this risk for some push-based setups, but it is not a replacement for phishing-resistant MFA.
- Phone-network attacks: SMS-based codes can be undermined by SIM swapping or SS7 exploitation, which is one reason CISA ranks text codes below stronger methods.
For workplace accounts
Follow your organization’s security policy and use the methods its systems support. CISA’s small-business guidance favors phishing-resistant MFA; if your workplace still uses push prompts, number matching may be an interim protection where available. Ask your IT or security team about approved enrollment and recovery steps rather than changing a managed account’s settings outside its process.
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #3
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

