Skip to content
Utah Community Learning

Turning on two-factor on your email and bank

About 25 minutes

Turning on two-factor on your email and bank

In the previous class we settled the text-versus-app argument. Text 2FA is fine. If that's the version you'll actually enable, that's the version to use. Today we stop discussing it and enable it — email first, then your bank. You have your backup-codes sheet from a couple of lessons back. Go retrieve it. If you can't find it, stop and look now, before you begin, not after you're locked out.

Email first, because email is the master key

If someone gets into your email, they can usually get into everything else. They click "forgot password" on your bank, on Amazon, on whatever, and the reset link arrives in the inbox they already control. So email gets two-factor before anything else.

The general path, whether it's Gmail, Outlook, Yahoo, or whatever you have:

  1. Log into your email on a computer, not your phone, if you can. It's easier to see what you're doing.
  2. Find "Security" in your account settings. It's usually one click from your profile picture or a gear icon.
  3. Look for "Two-Step Verification" or "Two-Factor Authentication." Different companies name it differently. Same concept.
  4. Turn it on. It will ask for a phone number for text codes. Provide one.
  5. It will very likely offer you backup codes at this point as well. Print them or write them down. Not a screenshot on the phone you might lose.
  6. Test it. Log out, log back in, and confirm the text code actually arrives and actually works before you walk away from the computer.

That last step matters more than people assume. I turned mine on, closed the laptop, felt good about myself, and went on with my Saturday. Later I switched phones and lost access to the app that was supposedly backing me up. Locked out of my own email for an hour. Since then I teach backup codes before I teach anything else, and I make you test it in the room, exactly as we did with the password manager. We're not leaving until yours works — remember.

Now the bank

Banks are usually further along on this than email providers, so it's often already half configured and you simply have to turn it on.

  1. Log into your bank's website or app.
  2. Look for "Security Settings" or "Login Settings." Sometimes it's buried under "Profile."
  3. Look for "Two-Factor Authentication" or "Extra Security" or something along those lines. Banks favor their own invented label for this. Move through the menu, read the items, and you'll find it.
  4. Enable text codes to your phone.
  5. Most banks won't provide backup codes the way email does. That's fine. If you're ever locked out of your bank, you call the number on the back of your card. We covered that a couple of lessons ago and it still applies here.

While you're in there, this is also a good moment to confirm that the phone number and email on file with the bank are actually current. I've seen people two-factor themselves straight into a wall because the code is going to a number they haven't used since 2019.

The excuse I hear most

My brother Kelly does not want to do this. Kelly does not want to do any of this. I showed him his password sitting on a breach list, plain as day, and he changed exactly one account. One. So I already know what someone in this room is thinking: "This is a hassle, I'll get to it."

Here is my candid opinion on that, and I know some of you have heard the opposite from a nephew who works in IT. The security purists will tell you text codes aren't the strongest option available. They're correct. An app-based code or a physical key is technically more secure. But none of that matters if you never enable any of it. Text 2FA that you actually use beats perfect security that sits in a settings menu untouched. That's the entire point. Don't let anyone shame you out of doing the version you'll actually do.

One thing to watch for

Once you enable this, you'll begin receiving text messages with six-digit codes. That's normal; that's it working. But scammers know this now too, and some of them will call pretending to be your bank, saying "we're sending you a code, read it back to us to verify your identity." Don't. A real code is something you type into a website you opened yourself. It is never something you read aloud to a stranger on the phone. If someone asks you to do that, hang up. Same rule as always.

Before next time

Get email and at least one bank account two-factored before we meet again. If you hit a screen you don't understand, take a picture of it and bring it in rather than guessing your way through. Guessing is how Kylie ended up letting a stranger onto her computer, and we don't need a repeat of that story.

~kenneth

Turning on two-factor on your email and bank — Online Safety and Scam Prevention · Utah Community Learning