How to turn on two-factor in WhatsApp, Instagram and Gmail

Two-step verification has the best effort-to-protection ratio in all of security: a few minutes to set up, and it turns a stolen password into a failed attempt. The difficulty is not the concept. It is that the setting is buried in a different menu in every single app.
Before touching any menu, two minutes of preparation that save a lot of grief.
Install an authenticator app. Google Authenticator, Microsoft Authenticator, Aegis, 2FAS, or whichever one your password manager includes. They all do the same thing: generate a six-digit number that changes every thirty seconds, with no connection required.
Decide where the recovery codes are going to live. Each service hands you a list of one-time codes when you enable verification. They are the master key for the day you lose your phone. Put them in your password manager, or printed in a drawer. Anywhere except the phone itself, which is precisely the thing you might lose. The long reasoning is in you lost the phone with your two-factor codes.
The order matters
Do not enable all three at once without thinking. Work in this order:
- Email. The root account. Everything else resets through it.
- Banking and payments, if they do not already require it.
- Social media, where your identity gets impersonated to your contacts.
- Everything else.
Gmail and your Google account
The Google account is the most important of the three, because your email, photos, Android phone and the recovery path for almost everything else hang off it.
- Open your Google account in a browser, or Settings → Google on the phone.
- The Security tab.
- Find 2-Step Verification and switch it on.
- Google defaults to prompts on your phone. That works well, but scroll down to Authenticator app and add that too: it is what saves you if that phone is gone.
- On the same screen, Backup codes. Generate and store them now, not “later”.
If you want to go a step further, Google supports passkeys, which replace the password with your device’s fingerprint or face. What they are exactly, and whether it is worth switching, is in passkeys: what they are and how they work.
WhatsApp: the PIN, which is not what it looks like
WhatsApp works differently, and this trips people up. There is no password: the account is tied to your phone number and verified by SMS. Which means whoever gets your number gets your WhatsApp.
WhatsApp’s two-step verification is a six-digit PIN requested when your number is registered on a new phone. It is the only thing standing between a SIM swap and your conversations.
- Settings → Account → Two-step verification.
- Turn on.
- Pick six digits that are not your date of birth or your card PIN.
- Add a recovery email address. Without it, forgetting the PIN locks you out of your own account for days.
Nobody from WhatsApp will ever ask for that PIN or for your registration code. This is exactly the scam described in SMS codes you never asked for: someone messages you posing as a friend, says they sent you a code by mistake, and asks you to forward it.
- Settings → Accounts Centre.
- Password and security → Two-factor authentication.
- Pick the account and choose Authentication app.
- Scan the code with your authenticator app and enter the six digits.
- Save the recovery codes that appear next.
Instagram and Facebook share the Accounts Centre, so if both are linked, enabling it covers the pair. While you are on that screen it is worth reviewing where you are logged in and ending anything you do not recognise — the step most people skip, and the one that actually evicts anybody already inside, as explained in someone got into my Instagram.
After enabling it: the test
The step almost nobody does, and the one that prevents the nasty surprise:
- Sign out on one device.
- Sign back in and check the code works.
- Check you know where your recovery codes are.
If something is wrong, it is infinitely better to find out now, while you are still signed in somewhere else, than in six months with a broken phone.
What not to do
- Do not store the recovery codes only on the phone that generates the codes.
- Do not use SMS as your only method if the service offers an app.
- Do not screenshot the QR code and leave it in your gallery: anyone with access to your photos could rebuild your second factor.
- Do not turn verification off “just for a minute” to do something quickly. It rarely goes back on.
The short version
- Save the recovery codes before enabling anything, and not on the phone.
- Start with email: it is the account everything else recovers through.
- WhatsApp’s two-factor is a PIN, and its job is to block a takeover of your number.
- On Instagram, enabling two-factor and ending unknown sessions belong together.
- Test that it works the same day, not when you need it.
Frequently asked
The questions that keep coming up
Where do I start if I am only going to protect one account?
Your email. It is the account every other one resets through: whoever controls your email can recover any other service in your name.
What is the WhatsApp PIN for?
It is a six-digit code WhatsApp asks for when your number is registered on a new phone. It stops anyone who takes over your number by SMS from using your account.
What happens if I lose my phone afterwards?
Nothing serious, provided you stored the recovery codes somewhere other than the phone. Without them recovery exists but is slow. Save them before you enable anything.
Authenticator app or SMS?
An app whenever possible. SMS is vulnerable to SIM swapping and readable from the lock screen. That said, SMS is still far better than nothing.


