Open account settings and enable 2FA with an authenticator app or email codes. Save the backup codes somewhere safe — they're your way in if you lose your device. Active sessions can be reviewed and signed out remotely at any time.
Quick answer
Open account settings, go to Security, and enable 2FA with an authenticator app (preferred) or email codes. Save the backup codes somewhere safe — they're your recovery path if you lose your phone.
Two-factor authentication (2FA) adds a second step to signing in, so even if someone has your password they can't get into your account. Open your account settings and go to Security.
Pick whichever fits — you can switch between them later, or use both.
When 2FA is on, you'll be given a set of backup codes. Each code works once and lets you sign in without your authenticator app or email. Save them somewhere secure — a password manager is ideal. If you lose your phone and don't have the codes, recovering your account takes much longer.
You can regenerate the backup codes at any time, which invalidates the old set.
A list of your active sessions — device, browser, location, last active time — lives in the 2FA section. You can sign any of them out remotely. Useful if you think your account has been compromised, or if you left yourself signed in on a shared computer.
When you sign in from a new device, after entering your password you'll be asked for:
Trusted devices can be remembered for a set period so you're not prompted on every sign-in.
You can disable 2FA from the same Security page. You'll be asked to confirm with your password. Once off, your account is back to password-only, so only do this if you have a specific reason — and consider turning it back on later.
Still need help with this article?
Send the article URL and the step that needs more explanation.