forumNew topic

What is two-factor authentication (2FA), how do I enable it and is it really secure?

VVildan D***Member
Job title
Quality control inspector
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Apr 2024
Message
160

Doki · Phishing awareness training · 2024

#1

They told me to enable 2FA on my Gmail account but I didn't quite understand what it is. Do I need to enter a password + something else? Will a code come via SMS or is there another method? Will I lose my account if I lose my phone?

The IT manager told us to enable 2FA on business accounts (Slack, GitHub, AWS), and when I did I used Google Authenticator. The app scanned the QR code now the codes show up in the app. But can the app be deleted too what are backup codes for?

Is it mandatory to enable 2FA on all systems? How is it managed when the number of people increases (100 people)? What happens if someone forgets?

JJale S***ExpertCommunity member
Joined
Dec 2024
Message
151
Most Helpful#2

2FA (two-factor authentication) requires a password + a second verifier. Types: 1) SMS OTP (Send code via SMS), 2) TOTP (Time-based OTP: Google Authenticator, Authy), 3) FIDO2/WebAuthn (Hardware key: YubiKey), 4) Backup codes (recovery codes). Preference order: FIDO2 > TOTP > SMS > Backup codes. SMS risk: SIM swap, interception. TOTP risk: if phone is lost, recover with backup codes. Setup: Gmail → Security → 2-Step Verification → enable TOTP app (Google Authenticator), scan QR code, get 10 backup codes (safe place), testing. If app is deleted: recovery with backup codes, otherwise account recovery process. Corporate: Mobile Device Management (MDM) + policy (TOTP mandatory), admin panel for 2FA and an antivirus product (trusted admin encryption table). 100+ people: centralized identity (Azure AD, Okta), SSO + 2FA policy enforce. Backup codes: safe deposit box, encrypted storage (password manager), print + safe.

SSena S***MemberCommunity member
Joined
May 2023
Message
175
#3

2fa = password + code it comes via sms or shows up in the authenticator app. authenticator is more secure sms can be hacked. save the backup codes well, otherwise the account stays locked. i make everyone use authenticator at the company...

VVildan Ş***Member
Job title
Quality control inspector
Sector
Textile
Organization type
medium-sized business
Joined
Aug 2024
Message
162
#4

2FA implementation: TOTP (RFC 6238) standard, 30-second window, 6-digit code. Tools: Google Authenticator, Microsoft Authenticator, Authy (cloud backup), FreeOTP. Hardware 2FA: YubiKey (FIDO2/U2F), $40-60, enterprise grade, phishing resistant. SMS 2FA risk: SS7 attack (SIM swap), not recommended for high security. Backup code entropy: 40-bit minimum (64 hex digits, 16 words), generated & hashed server-side. Account recovery: email backup, SMS backup, security questions (NOT recommended). MDM integration: Intune, MobileIron enforce 2FA unlock.

UUğur V***MemberCommunity member
Joined
Aug 2023
Message
282
#5

don't forget the backup codes when enabling 2FA bro, they save your ass. scan the QR code with your authenticator app, save 10-15 codes (not in cloud) done. if you lose your phone you can recover your account with the backup codes. don't use SMS at all, people phish...

KKemal G***Member
Job title
Store associate
Sector
IT services
Organization type
medium-sized business
Joined
Apr 2023
Message
7

Doki · Incident response support · 2024

#6

2FA workflow: 1) Enable TOTP (authenticator app), 2) Generate & save backup codes, 3) Test login + 2FA 4) Store backup codes offline (vault, print), 5) Share recovery procedures (team). Enterprise: centralized policy (conditional access) admin antivirus product capability audit logging. Challenges: user adoption (friction), device loss (recovery process) cost (hardware 2FA). Mitigation: education recovery playbooks, MDM + conditional access (auto-enroll).

RRecep T***Member
Job title
Sales Manager
Sector
Accounting & advisory
Organization type
cooperative
Joined
Dec 2023
Message
2

Doki · SEO consulting · 2023

#7

you become 10 million times safer once you turn on 2FA!!! password + code even hackers cant catch both at the same time. write the backup codes on a piece of ppaer put it in the safe, download the code to your phone too, sleep easy...

SSultan Ç***New memberCommunity member
Joined
Aug 2026
Message
7
#8

Looking at it as a process, the picture changes. When making decisions, write down the worst-case scenario too, not just the best.

I'm also curious if anyone does it differently.

FFatma G***Member
Job title
Content Editor
Sector
Energy
Organization type
boutique agency
Joined
Aug 2024
Message
21
#9

if you're going this route sort this out first. an automated scan report is not the same as a penetration test.

just leaving this note it might be useful.

MMustafa C***MemberCommunity member
Joined
Jan 2026
Message
96
#10

Thanks for writing this, that's the right way. Trying to do this alone is the most expensive way.

If I were you, I'd go this route.

ŞŞerife K***Veteran
Job title
Clinic manager
Sector
Electrical-electronics
Organization type
early-stage startup
Joined
Dec 2023
Message
128
#11

This is exactly what we experienced. If permission and scope aren't in writing, don't start that test.

This is my opinion I'm not claiming it's absolute truth.

İİsmail K***New member
Job title
Grocery
Organization type
medium-sized business
Joined
Dec 2024
Message
22

Doki · Log management setup · 2025

#12

let me clarify the technical side. don't rely on a single measure; go layer by layer.

if I were you I'd go this route.

AAslı G***ExpertCommunity member
Joined
Jan 2023
Message
1
#13

Quick summary for newcomers: If you don't write this down from the start, it leads to arguments later.

Of course, it varies if your situation is different.

SSelim C***MemberCommunity member
Joined
Nov 2025
Message
53
#14

There's a trap here, let me mention it. If you scold false alarms, nobody will report again.

That's all sorry if I went on too long.

HHasan U***MemberCommunity member
Joined
May 2024
Message
41
#15

Let me share what happened to me; it might be useful. Forgotten test environments are more often the entry point than live systems.

If you post the result here, it will help others too.

NNecati B***MemberCommunity member
Joined
Dec 2024
Message
86
#16

Im in the same situation thats why Im asking. An automated scan report is not the same as a penetration test.

This is my opinion I'm not claiming it's absolute truth.

AAleyna G***MemberCommunity member
Joined
Nov 2024
Message
54
#17

Let me summarize the topic, since several different answers were given. When making a decision, first look at what data you have on hand.

Correct me if I'm wrong.

MMeryem U***Member
Job title
Secretary
Sector
Packaging
Organization type
family business
Joined
Nov 2023
Message
300
#18

Following. Your time to detect an issue directly determines its cost.

Trying to do this alone is the most expensive way. I'm also curious if anyone does it differently.

MMelis Ö***Expert
Job title
Social media manager
Sector
E-commerce
Organization type
120-person company
Joined
Feb 2022
Message
14

Doki · Log management setup · 2025

#19

I partly agree, partly disagree. Processes without records never improve, because you don't know what to fix.

Processes without records never improve, because you don't know what to fix.

EElif Y***Member
Job title
Site Manager
Sector
Media and publishing
Organization type
20-person company
Joined
Mar 2024
Message
5
#20

Let me share my experience. Just because everyone does it doesn't mean it's right.

This is my opinion, I'm not claiming it's absolute truth.

Reply