
How to Set Up 2FA on Instagram, Facebook and TikTok
Which 2FA method to pick, how to turn it on for Instagram, Facebook and TikTok, where to keep backup codes, and what 2FA still cannot stop.
Secure the email behind each account first, then turn on 2FA with an authenticator app as your main method: Instagram and Facebook through Accounts Center, TikTok under Security and permissions. Add a passkey where offered and keep SMS only as a backup. Save backup codes offline, away from your phone, and never share any code with anyone.
Summary- Two-factor authentication means a stolen password is not enough on its own, but it only helps if it is set up with the right method.
- Secure the email behind each account first, with a unique password and its own two-step verification, because that inbox can reset the account.
- Use an authenticator app as your main method, add a passkey or security key where offered, and keep SMS only as a backup.
- Save Instagram backup codes and Facebook recovery codes offline, away from your phone, turn on login alerts and log out devices you do not recognise.
- 2FA cannot stop you typing a code into a fake page or reading one to a scammer. No real support team ever asks for your codes.
- Good 2FA makes recovery far more likely, but only the platform can restore an account and nobody outside it can promise an outcome.
Table of contents14 sections
- 01What is the best way to set up 2FA on Instagram, Facebook and TikTok?
- 02What two-factor authentication actually does
- 03Secure your email account before you touch 2FA
- 04Which 2FA method should you choose?
- 05How to turn on 2FA on Instagram
- 06How to turn on 2FA on Facebook through Accounts Center
- 07How to turn on 2-step verification on TikTok
- 08Backup and recovery codes: where to keep them
- 09Login alerts, trusted devices and where you are logged in
- 10Common 2FA mistakes that still lead to takeovers
- 11What 2FA does not protect against
- 122FA setup checklist
- 13If you are already locked out or have just been hacked
- 14Frequently Asked Questions
Your cousin's Instagram started posting crypto giveaways at 2am. By breakfast, the attacker had messaged half the family asking for "urgent" bank transfers, and the recovery email on the account belonged to someone else. You open your own Instagram, Facebook and TikTok and realise you have never checked what protects them beyond a password you have used since secondary school.
Two-factor authentication (2FA) is the setting that fixes most of that. It means a stolen password is not enough on its own. The catch is that 2FA set up badly can lock you out after a phone change, and 2FA set up with the wrong method can still be phished. This guide covers which method to pick on each platform, how to turn it on at the time of writing, where to keep backup codes, and the tricks that still work against accounts with 2FA switched on.
Last checked: 28 September 2026.
#What is the best way to set up 2FA on Instagram, Facebook and TikTok?
Secure the email account behind each profile first, because whoever controls that inbox can reset the social account. Then turn on 2FA with an authenticator app as your main method on all three platforms: Instagram and Facebook through "Accounts Center", TikTok under "Security & permissions". Add a passkey or, on Facebook, a security key where it is offered, since those resist fake login pages. Keep SMS only as a backup. Save Instagram's backup codes and Facebook's recovery codes offline, away from your phone. Turn on login alerts and remove devices you do not recognise. Finally, remember what 2FA cannot do: it cannot stop you typing a code into a fake page, reading one out to a scammer, or clicking a link that hands over your logged-in session.
#What two-factor authentication actually does
2FA adds a second check after your password. When someone logs in from a device the platform does not recognise, it asks for a code or a confirmation that only you should have. Instagram's help page on securing your account with two-factor authentication describes it exactly that way: a code is required if there is a login attempt from a device Meta does not recognise.
That stops a common kind of takeover: someone who bought, guessed or reused your password from another leak. It does much less against an attacker who gets you to do the second step for them. Keep that split in mind, because it decides which method you should pick.
#Secure your email account before you touch 2FA
Do this first. If an attacker controls the email address on your Instagram, Facebook or TikTok, they can often reset the password and change your 2FA from there. A perfectly configured authenticator app does not help if the inbox behind it is open.
- Give the email account a long, unique password that you use nowhere else.
- Turn on the email provider's own two-step verification. Google's 2-Step Verification guide supports passkeys, security keys, Google prompts, authenticator apps and text codes, and notes that text and call codes are more exposed to phone number attacks.
- Check the recovery phone and recovery email on the inbox itself, and remove any you do not recognise.
- Look for forwarding rules or filters you did not create, which can hide security alerts from you.
If you have already lost access to that email or its phone number, stop here and read our guide to getting back in without your old phone, email or 2FA codes before changing anything else.
#Which 2FA method should you choose?
Pick the strongest method each platform offers, then add a second one so a lost phone does not lock you out. The order that security agencies use is simple: phishing-resistant methods first, authenticator apps second, text messages last.
CISA, the US Cybersecurity and Infrastructure Security Agency, sets out that ranking in two documents. Its phishing-resistant MFA fact sheet (October 2022) says any form of MFA is better than no MFA, but calls phishing-resistant MFA the gold standard, and lists SIM swaps and SS7 network weaknesses among the ways attackers get hold of text codes. Goal 3.F of its Cross-Sector Cybersecurity Performance Goals 2.0 (December 2025) ranks MFA from strongest to weakest: phishing-resistant MFA such as FIDO/WebAuthn, then app-based methods, and SMS or voice only when nothing else is possible. Both are written for organisations, but the ranking holds for a personal account too.
| Method | Protection | Main risk | Available on (at the time of writing) |
|---|---|---|---|
| Passkey | Strongest. Uses your phone's fingerprint, face or screen lock and only works on the real site | Not offered to every account or device yet | Facebook, Instagram (Meta says not everyone has it yet), TikTok |
| Security key | Strongest. A physical FIDO key you tap or plug in, tied to the real site | You must buy one, and a lost key needs a backup method | Facebook. Not listed on Instagram's or TikTok's 2FA pages |
| Authenticator app | Strong. Codes are made on your phone, not sent to it | Can still be typed into a fake login page. Lost with the phone if not backed up | Instagram, Facebook, TikTok |
| SMS code | Better than nothing. Stops password-only attacks | SIM swaps, recycled numbers, and codes read out to scammers | Instagram, Facebook, TikTok |
| WhatsApp code | Similar to SMS | Tied to the same phone number, and Instagram needs SMS turned on first | |
| Email code | Only as strong as the inbox | Anyone in your email gets the code too | TikTok |
| Backup or recovery codes | Your emergency route, not a daily method | Useless if stored on the phone you lost, dangerous if anyone else sees them | Instagram (backup codes), Facebook (recovery codes) |
A passkey is a login method stored on your device that you unlock with your fingerprint, face or screen lock. Because it is bound to the real website, a fake login page has nothing to collect. Meta and TikTok offer passkeys alongside 2FA rather than as one of the options inside the 2FA menu, so add one where you see it and keep 2FA switched on as well.
#How to turn on 2FA on Instagram
Instagram's 2FA page lists three methods: authentication app (which Instagram recommends), text message and WhatsApp. It also notes that the authentication app method can only be turned on from the Instagram app for Android and iPhone, not from a browser. At the time of writing, the steps are:
- Open the Instagram app, go to your profile, tap the menu and open Settings. Meta is moving people from "Accounts Center" to "Meta Account settings", so you may see either name.
- Tap "Accounts Center" (or "Meta Account settings"), then "Password and security".
- Tap "Two-factor authentication" and select your Instagram account.
- Choose "Authentication app". Scan the QR code with your authenticator app, or copy the setup key into it by hand.
- Type the six-digit code the app shows to confirm.
- Go back to the same screen, open "Additional methods", then "Backup codes", and save them offline (see the backup codes section below).
- Add text message as a second method if you want a fallback. Only then add WhatsApp, which Instagram allows once text message is on.
Instagram says an authenticator app can be added on more than one device, which is useful if you keep a tablet at home. If your Threads profile logs in with your Instagram account, securing Instagram protects Threads as well; our guide to a hacked or suspended Threads account covers the Threads side.
#How to turn on 2FA on Facebook through Accounts Center
Facebook's page on how two-factor authentication works lists three methods: tapping a security key, codes from an authentication app, and text message codes. It also offers ten one-time recovery codes. At the time of writing:
- Tap or click your profile picture, then "Settings and privacy", then "Settings".
- Open "Accounts Center" (or "Meta Account settings"), then "Password and security".
- Tap "Two-factor authentication" and choose your Facebook account.
- Choose "Authentication app" and scan the QR code, or choose "Security key" if you own one.
- Enter the code or tap the key to confirm.
- Under "Additional methods", open "Recovery codes" and tap "Get new codes". Facebook gives you ten, and each works once (Facebook: recovery codes).
If you use a security key on Facebook, Facebook advises registering a second key or another 2FA method, so losing the key does not lock you out. Facebook also offers passkeys, created under "Password and security" and unlocked with your device's screen lock.
If Instagram and Facebook sit in the same Accounts Center, repeat the steps for each profile. Turning on 2FA for one does not always cover the other.
#How to turn on 2-step verification on TikTok
TikTok calls it 2-step verification and requires at least two methods from phone, email, authenticator and password. TikTok's help centre names Google Authenticator and Microsoft Authenticator as examples of apps that work. At the time of writing:
- Tap "Profile", then the menu button at the top, then "Settings and privacy".
- Tap "Security & permissions", then "2-step verification".
- Select "Authenticator" and at least one more method. Authenticator plus email is a sensible pair, provided the email account is secured as above.
- For the authenticator, scan the QR code or copy the key into your app, then enter the code it shows.
- Tap "Turn on" to confirm.
- For phone or email, enter the verification code TikTok sends.
On the same "Security & permissions" screen, open "Security checkup". TikTok says it lets you link and verify your phone and email, turn on 2-step verification, manage trusted devices, review recent security activity and add a passkey. If you run a shop or ads, turn on 2-step verification for each person with access too. Our page on TikTok account recovery covers what happens when a TikTok account is already lost.
#Backup and recovery codes: where to keep them
Backup codes are one-time codes you save in advance, for the day your phone is lost, stolen or broken. They are the difference between a five-minute login and a long identity check. They only help if they are somewhere other than the phone.
- Print them or write them down, and keep them with your IC, passport or other important papers.
- Or keep them in a password manager that is itself protected with a strong method, and that you can open from another device.
- Do not keep them only in your phone's gallery, notes app or email drafts. Instagram's own page suggests a screenshot as one option, but a screenshot on the phone you lose is no help.
- Label which account each set belongs to. If you manage several Instagram profiles, each has its own codes.
- Generate a new set if anyone else may have seen them. On Instagram and Facebook, getting new codes cancels the old set.
- Never type them anywhere except the platform's own login screen, and never send them to anyone.
#Login alerts, trusted devices and where you are logged in
2FA only asks for a code on devices the platform does not recognise. That makes the list of recognised devices part of your security, and login alerts your early warning.
- Login alerts: Meta's Accounts Center manages login alerts, login activity and "Where you're logged in" for Instagram and Facebook together (Meta: Accounts Center settings). Facebook sends an alert by email, or by text if you choose, when someone logs in from an unrecognised device or browser.
- Trusted devices: when you log in with 2FA, Instagram offers "Trust this device" and Facebook offers to save the browser, so you are not asked for a code again there. Only accept on a phone or computer that is yours and not shared.
- Where you are logged in: Instagram's page on recent login activity shows how to log out devices you do not recognise. Do it now, and again whenever an alert looks wrong.
- TikTok: the security checkup lists trusted devices and recent security activity in one place.
#Common 2FA mistakes that still lead to takeovers
These are patterns, not rare edge cases. Each one leaves 2FA switched on but gives an attacker, or bad luck, a way around it.
- Sharing a code. A friend's hacked account, a fake courier or a fake "Meta Support" page asks for the six-digit code you just received. Whoever has that code has the login.
- SMS as the only method. If someone moves your number to a new SIM, or your number is reissued, the codes go to them. An unexpected "No service" on your phone is a reason to call your mobile provider straight away.
- Letting a prepaid number lapse. Fahmi Fadzil, then Communications and Digital Minister, told the Dewan Rakyat in October 2023 that under MCMC's numbering plan, inactive numbers go through a six-month quarantine before they can be reused by a new user (The Edge Malaysia). Move 2FA off a number before you give it up.
- Everything on one phone. The authenticator app, the SMS number, the email app and the backup-code screenshot all disappear together when the phone does. Move the authenticator before you wipe or trade in an old phone.
- A freelancer's or former staff member's number on a business account. Recovery details should belong to someone who will still be around next year.
- Trusting a shared device. "Trust this device" on a family tablet or office PC skips the code for anyone who picks it up.
#What 2FA does not protect against
2FA protects the login step. It does not protect a login you complete on someone else's behalf, and it does not protect a session that is already open. Two kinds of attack sit outside what codes can stop.
The first is a code handed to a scammer. On a fake login page, you type your password and the six-digit code yourself, and the attacker uses both within seconds. The same happens when someone persuades you to read a code out or forward it. App codes and SMS codes both fail here; passkeys and security keys resist it because they will not work on the wrong website. Our breakdown of the fake Meta support scam in Malaysia shows how these messages usually read, often a copyright or "your account will be disabled" warning with a link.
The second is session theft. If someone copies your logged-in session, they can use your account without knowing your password or passing 2FA, because the platform thinks you already did. This usually starts with a malicious link, a fake app or a bad browser extension. Meta's help centre warns about malware designed to steal login information, including software posing as browser extensions or popular apps. Logging out of all devices and changing your password ends the stolen session.
#2FA setup checklist
- The email behind each account has a unique password and its own two-step verification.
- Instagram, Facebook and TikTok each use an authenticator app as the main 2FA method.
- A passkey is added wherever the platform offers one, and a security key on Facebook if you own one.
- Each account has a second method that does not depend on the same phone alone.
- Instagram backup codes and Facebook recovery codes are stored offline and labelled.
- Login alerts are on, and unknown devices are logged out.
- "Trust this device" is used only on your own, unshared devices.
- The phone number on each account is current, active and yours.
- Your authenticator app is backed up or can be moved before you change phones.
- You have agreed with family or staff that nobody ever shares a login code.
#If you are already locked out or have just been hacked
This guide is about prevention. If someone is already inside your account, start with what to do in the first hour after an Instagram hack, then come back here to rebuild 2FA once you are in. For businesses and creators with several accounts and admins, our social account security checklist for Malaysian businesses covers admin seats, agencies and incident plans that go beyond one person's 2FA.
SocialSafe by AwareXone is AwareXone's recovery service. Where official routes are stuck, our team reviews the case before anything is agreed and works only through the platforms' own forms and appeals. For people who want help hardening accounts before anything goes wrong, our account security service sets up 2FA, recovery details and device hygiene with you. How we work and what we never ask for is published, including that we never need your password or codes.
#Frequently Asked Questions
Is SMS two-factor authentication better than nothing?
Which authenticator app should I use for Instagram, Facebook and TikTok?
Does a passkey replace two-factor authentication?
I had 2FA turned on and still got hacked. How?
What happens to my 2FA when I change phones?
Should I tap "Trust this device" when I log in?
Does WhatsApp 2FA on Instagram protect me from a SIM swap?
Will Meta or TikTok ever ask me to send them a login code?
Can I set up 2FA for a business Page or TikTok Shop the same way?
Official sources
- Instagram Help Center: Securing your Meta Account with two-factor authentication (accessed 28 September 2026)
- Instagram Help Center: How you can use a backup code on Instagram (accessed 28 September 2026)
- Instagram Help Center: View your Instagram account's recent login activity (accessed 28 September 2026)
- Facebook Help Center: How two-factor authentication works on Facebook (accessed 28 September 2026)
- Facebook Help Center: Set up Facebook login recovery codes (accessed 28 September 2026)
- Facebook Help Center: How security keys work on Facebook (accessed 28 September 2026)
- Facebook Help Center: Create a passkey on Facebook (accessed 28 September 2026)
- Facebook Help Center: Protect your account from malicious software designed to steal your login information (accessed 28 September 2026)
- Meta Help Center: Account settings you will be able to manage in Accounts Center (accessed 28 September 2026)
- Facebook Help Center: How Facebook uses your Accounts Center contact information for security notifications (accessed 28 September 2026)
- Meta Help Center: About Meta passkeys (accessed 28 September 2026)
- TikTok Support: Account safety, security checkup and 2-step verification (accessed 28 September 2026)
- TikTok Support: Account safety (accessed 28 September 2026)
- Google Account Help: Turn on 2-Step Verification (accessed 28 September 2026)
- CISA: Implementing Phishing-Resistant MFA, fact sheet (October 2022)
- CISA: Cross-Sector Cybersecurity Performance Goals 2.0, goal 3.F (December 2025)
- The Edge Malaysia: Over 70% of active phone numbers on prepaid plans, says Fahmi (24 October 2023)
Need help with your account?
Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Account security.




