# How to Set Up 2FA on Instagram, Facebook and TikTok

> Which 2FA method to pick, how to turn it on for Instagram, Facebook and TikTok, where to keep backup codes, and what 2FA still cannot stop.

- URL: https://www.awarexone.com/research/two-factor-authentication-instagram-facebook-tiktok
- Author: Md Shariar Shanaz Shuvon, Founder & CEO, AwareXone
- Published: 2026-09-28
- Topics: Account security, 2FA, Malaysia
- Related service: Account security: https://www.awarexone.com/services/account-security

## Short answer

Secure the email behind each account first, then turn on 2FA with an authenticator app as your main method: Instagram and Facebook through Accounts Center, TikTok under Security and permissions. Add a passkey where offered and keep SMS only as a backup. Save backup codes offline, away from your phone, and never share any code with anyone.

## Summary

- Two-factor authentication means a stolen password is not enough on its own, but it only helps if it is set up with the right method.
- Secure the email behind each account first, with a unique password and its own two-step verification, because that inbox can reset the account.
- Use an authenticator app as your main method, add a passkey or security key where offered, and keep SMS only as a backup.
- Save Instagram backup codes and Facebook recovery codes offline, away from your phone, turn on login alerts and log out devices you do not recognise.
- 2FA cannot stop you typing a code into a fake page or reading one to a scammer. No real support team ever asks for your codes.
- Good 2FA makes recovery far more likely, but only the platform can restore an account and nobody outside it can promise an outcome.

Your cousin's Instagram started posting crypto giveaways at 2am. By breakfast, the attacker had messaged half the family asking for "urgent" bank transfers, and the recovery email on the account belonged to someone else. You open your own Instagram, Facebook and TikTok and realise you have never checked what protects them beyond a password you have used since secondary school.

Two-factor authentication (2FA) is the setting that fixes most of that. It means a stolen password is not enough on its own. The catch is that 2FA set up badly can lock you out after a phone change, and 2FA set up with the wrong method can still be phished. This guide covers which method to pick on each platform, how to turn it on at the time of writing, where to keep backup codes, and the tricks that still work against accounts with 2FA switched on.

Last checked: 28 September 2026.

## What is the best way to set up 2FA on Instagram, Facebook and TikTok?

Secure the email account behind each profile first, because whoever controls that inbox can reset the social account. Then turn on 2FA with an authenticator app as your main method on all three platforms: Instagram and Facebook through "Accounts Center", TikTok under "Security & permissions". Add a passkey or, on Facebook, a security key where it is offered, since those resist fake login pages. Keep SMS only as a backup. Save Instagram's backup codes and Facebook's recovery codes offline, away from your phone. Turn on login alerts and remove devices you do not recognise. Finally, remember what 2FA cannot do: it cannot stop you typing a code into a fake page, reading one out to a scammer, or clicking a link that hands over your logged-in session.

## What two-factor authentication actually does

2FA adds a second check after your password. When someone logs in from a device the platform does not recognise, it asks for a code or a confirmation that only you should have. Instagram's help page on [securing your account with two-factor authentication](https://help.instagram.com/566810106808145) describes it exactly that way: a code is required if there is a login attempt from a device Meta does not recognise.

That stops a common kind of takeover: someone who bought, guessed or reused your password from another leak. It does much less against an attacker who gets you to do the second step for them. Keep that split in mind, because it decides which method you should pick.

## Secure your email account before you touch 2FA

Do this first. If an attacker controls the email address on your Instagram, Facebook or TikTok, they can often reset the password and change your 2FA from there. A perfectly configured authenticator app does not help if the inbox behind it is open.

- Give the email account a long, unique password that you use nowhere else.
- Turn on the email provider's own two-step verification. Google's [2-Step Verification guide](https://support.google.com/accounts/answer/185839) supports passkeys, security keys, Google prompts, authenticator apps and text codes, and notes that text and call codes are more exposed to phone number attacks.
- Check the recovery phone and recovery email on the inbox itself, and remove any you do not recognise.
- Look for forwarding rules or filters you did not create, which can hide security alerts from you.

If you have already lost access to that email or its phone number, stop here and read our guide to [getting back in without your old phone, email or 2FA codes](https://www.awarexone.com/research/lost-email-phone-2fa-account-recovery) before changing anything else.

## Which 2FA method should you choose?

Pick the strongest method each platform offers, then add a second one so a lost phone does not lock you out. The order that security agencies use is simple: phishing-resistant methods first, authenticator apps second, text messages last.

CISA, the US Cybersecurity and Infrastructure Security Agency, sets out that ranking in two documents. Its [phishing-resistant MFA fact sheet](https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf) (October 2022) says any form of MFA is better than no MFA, but calls phishing-resistant MFA the gold standard, and lists SIM swaps and SS7 network weaknesses among the ways attackers get hold of text codes. Goal 3.F of its [Cross-Sector Cybersecurity Performance Goals 2.0](https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0) (December 2025) ranks MFA from strongest to weakest: phishing-resistant MFA such as FIDO/WebAuthn, then app-based methods, and SMS or voice only when nothing else is possible. Both are written for organisations, but the ranking holds for a personal account too.

*Use two methods on every account: the strongest one available, plus a backup that does not live on the same phone.*

| Method | Protection | Main risk | Available on (at the time of writing) |
| --- | --- | --- | --- |
| Passkey | Strongest. Uses your phone's fingerprint, face or screen lock and only works on the real site | Not offered to every account or device yet | Facebook, Instagram (Meta says not everyone has it yet), TikTok |
| Security key | Strongest. A physical FIDO key you tap or plug in, tied to the real site | You must buy one, and a lost key needs a backup method | Facebook. Not listed on Instagram's or TikTok's 2FA pages |
| Authenticator app | Strong. Codes are made on your phone, not sent to it | Can still be typed into a fake login page. Lost with the phone if not backed up | Instagram, Facebook, TikTok |
| SMS code | Better than nothing. Stops password-only attacks | SIM swaps, recycled numbers, and codes read out to scammers | Instagram, Facebook, TikTok |
| WhatsApp code | Similar to SMS | Tied to the same phone number, and Instagram needs SMS turned on first | Instagram |
| Email code | Only as strong as the inbox | Anyone in your email gets the code too | TikTok |
| Backup or recovery codes | Your emergency route, not a daily method | Useless if stored on the phone you lost, dangerous if anyone else sees them | Instagram (backup codes), Facebook (recovery codes) |

A passkey is a login method stored on your device that you unlock with your fingerprint, face or screen lock. Because it is bound to the real website, a fake login page has nothing to collect. Meta and TikTok offer passkeys alongside 2FA rather than as one of the options inside the 2FA menu, so add one where you see it and keep 2FA switched on as well.

## How to turn on 2FA on Instagram

Instagram's 2FA page lists three methods: authentication app (which Instagram recommends), text message and WhatsApp. It also notes that the authentication app method can only be turned on from the Instagram app for Android and iPhone, not from a browser. At the time of writing, the steps are:

1. Open the Instagram app, go to your profile, tap the menu and open Settings. Meta is moving people from "Accounts Center" to "Meta Account settings", so you may see either name.
2. Tap "Accounts Center" (or "Meta Account settings"), then "Password and security".
3. Tap "Two-factor authentication" and select your Instagram account.
4. Choose "Authentication app". Scan the QR code with your authenticator app, or copy the setup key into it by hand.
5. Type the six-digit code the app shows to confirm.
6. Go back to the same screen, open "Additional methods", then "Backup codes", and save them offline (see the backup codes section below).
7. Add text message as a second method if you want a fallback. Only then add WhatsApp, which Instagram allows once text message is on.

Instagram says an authenticator app can be added on more than one device, which is useful if you keep a tablet at home. If your Threads profile logs in with your Instagram account, securing Instagram protects Threads as well; our guide to a [hacked or suspended Threads account](https://www.awarexone.com/research/threads-account-hacked-suspended) covers the Threads side.

## How to turn on 2FA on Facebook through Accounts Center

Facebook's page on [how two-factor authentication works](https://www.facebook.com/help/148233965247823) lists three methods: tapping a security key, codes from an authentication app, and text message codes. It also offers ten one-time recovery codes. At the time of writing:

1. Tap or click your profile picture, then "Settings and privacy", then "Settings".
2. Open "Accounts Center" (or "Meta Account settings"), then "Password and security".
3. Tap "Two-factor authentication" and choose your Facebook account.
4. Choose "Authentication app" and scan the QR code, or choose "Security key" if you own one.
5. Enter the code or tap the key to confirm.
6. Under "Additional methods", open "Recovery codes" and tap "Get new codes". Facebook gives you ten, and each works once ([Facebook: recovery codes](https://www.facebook.com/help/148104135383285)).

If you use a [security key on Facebook](https://www.facebook.com/help/401566786855239), Facebook advises registering a second key or another 2FA method, so losing the key does not lock you out. Facebook also offers [passkeys](https://www.facebook.com/help/1181045243159511), created under "Password and security" and unlocked with your device's screen lock.

If Instagram and Facebook sit in the same Accounts Center, repeat the steps for each profile. Turning on 2FA for one does not always cover the other.

## How to turn on 2-step verification on TikTok

TikTok calls it 2-step verification and requires at least two methods from phone, email, authenticator and password. TikTok's help centre names Google Authenticator and Microsoft Authenticator as examples of apps that work. At the time of writing:

1. Tap "Profile", then the menu button at the top, then "Settings and privacy".
2. Tap "Security & permissions", then "2-step verification".
3. Select "Authenticator" and at least one more method. Authenticator plus email is a sensible pair, provided the email account is secured as above.
4. For the authenticator, scan the QR code or copy the key into your app, then enter the code it shows.
5. Tap "Turn on" to confirm.
6. For phone or email, enter the verification code TikTok sends.

On the same "Security & permissions" screen, open "Security checkup". TikTok says it lets you link and verify your phone and email, turn on 2-step verification, manage trusted devices, review recent security activity and add a passkey. If you run a shop or ads, turn on 2-step verification for each person with access too. Our page on [TikTok account recovery](https://www.awarexone.com/social-media-recovery/tiktok-account-recovery) covers what happens when a TikTok account is already lost.

## Backup and recovery codes: where to keep them

Backup codes are one-time codes you save in advance, for the day your phone is lost, stolen or broken. They are the difference between a five-minute login and a long identity check. They only help if they are somewhere other than the phone.

- Print them or write them down, and keep them with your IC, passport or other important papers.
- Or keep them in a password manager that is itself protected with a strong method, and that you can open from another device.
- Do not keep them only in your phone's gallery, notes app or email drafts. Instagram's own page suggests a screenshot as one option, but a screenshot on the phone you lose is no help.
- Label which account each set belongs to. If you manage several Instagram profiles, each has its own codes.
- Generate a new set if anyone else may have seen them. On Instagram and Facebook, getting new codes cancels the old set.
- Never type them anywhere except the platform's own login screen, and never send them to anyone.

> Warning: **Backup codes are keys, not paperwork.** No real support team asks for backup codes, recovery codes or login codes. That includes Meta, TikTok and AwareXone. A message that asks you to "confirm" them is an attempt to take the account.

## Login alerts, trusted devices and where you are logged in

2FA only asks for a code on devices the platform does not recognise. That makes the list of recognised devices part of your security, and login alerts your early warning.

- Login alerts: Meta's Accounts Center manages login alerts, login activity and "Where you're logged in" for Instagram and Facebook together ([Meta: Accounts Center settings](https://www.meta.com/help/accounts-center/841741830388205/)). Facebook sends an alert by email, or by text if you choose, when someone logs in from an unrecognised device or browser.
- Trusted devices: when you log in with 2FA, Instagram offers "Trust this device" and Facebook offers to save the browser, so you are not asked for a code again there. Only accept on a phone or computer that is yours and not shared.
- Where you are logged in: Instagram's page on [recent login activity](https://help.instagram.com/2761108904184084/) shows how to log out devices you do not recognise. Do it now, and again whenever an alert looks wrong.
- TikTok: the security checkup lists trusted devices and recent security activity in one place.

## Common 2FA mistakes that still lead to takeovers

These are patterns, not rare edge cases. Each one leaves 2FA switched on but gives an attacker, or bad luck, a way around it.

- Sharing a code. A friend's hacked account, a fake courier or a fake "Meta Support" page asks for the six-digit code you just received. Whoever has that code has the login.
- SMS as the only method. If someone moves your number to a new SIM, or your number is reissued, the codes go to them. An unexpected "No service" on your phone is a reason to call your mobile provider straight away.
- Letting a prepaid number lapse. Fahmi Fadzil, then Communications and Digital Minister, told the Dewan Rakyat in October 2023 that under MCMC's numbering plan, inactive numbers go through a six-month quarantine before they can be reused by a new user ([The Edge Malaysia](https://theedgemalaysia.com/node/687380)). Move 2FA off a number before you give it up.
- Everything on one phone. The authenticator app, the SMS number, the email app and the backup-code screenshot all disappear together when the phone does. Move the authenticator before you wipe or trade in an old phone.
- A freelancer's or former staff member's number on a business account. Recovery details should belong to someone who will still be around next year.
- Trusting a shared device. "Trust this device" on a family tablet or office PC skips the code for anyone who picks it up.

## What 2FA does not protect against

2FA protects the login step. It does not protect a login you complete on someone else's behalf, and it does not protect a session that is already open. Two kinds of attack sit outside what codes can stop.

The first is a code handed to a scammer. On a fake login page, you type your password and the six-digit code yourself, and the attacker uses both within seconds. The same happens when someone persuades you to read a code out or forward it. App codes and SMS codes both fail here; passkeys and security keys resist it because they will not work on the wrong website. Our breakdown of the [fake Meta support scam in Malaysia](https://www.awarexone.com/research/fake-meta-support-scam-malaysia) shows how these messages usually read, often a copyright or "your account will be disabled" warning with a link.

The second is session theft. If someone copies your logged-in session, they can use your account without knowing your password or passing 2FA, because the platform thinks you already did. This usually starts with a malicious link, a fake app or a bad browser extension. Meta's help centre warns about [malware designed to steal login information](https://www.facebook.com/help/773912954219636), including software posing as browser extensions or popular apps. Logging out of all devices and changing your password ends the stolen session.

> Warning: **A code is only for the screen that asked for it.** If a login code arrives that you did not request, someone may already have your password. Do not share the code. Open the app directly, not a link, change the password and check where you are logged in. If money has already been lost to a related scam, call your bank's hotline or the National Scam Response Centre on 997 immediately, then make a police report.

## 2FA setup checklist

- The email behind each account has a unique password and its own two-step verification.
- Instagram, Facebook and TikTok each use an authenticator app as the main 2FA method.
- A passkey is added wherever the platform offers one, and a security key on Facebook if you own one.
- Each account has a second method that does not depend on the same phone alone.
- Instagram backup codes and Facebook recovery codes are stored offline and labelled.
- Login alerts are on, and unknown devices are logged out.
- "Trust this device" is used only on your own, unshared devices.
- The phone number on each account is current, active and yours.
- Your authenticator app is backed up or can be moved before you change phones.
- You have agreed with family or staff that nobody ever shares a login code.

## If you are already locked out or have just been hacked

This guide is about prevention. If someone is already inside your account, start with [what to do in the first hour after an Instagram hack](https://www.awarexone.com/research/instagram-hacked-first-hour), then come back here to rebuild 2FA once you are in. For businesses and creators with several accounts and admins, our [social account security checklist for Malaysian businesses](https://www.awarexone.com/research/social-media-security-malaysia) covers admin seats, agencies and incident plans that go beyond one person's 2FA.

SocialSafe by AwareXone is AwareXone's recovery service. Where official routes are stuck, our team reviews the case before anything is agreed and works only through the platforms' own forms and appeals. For people who want help hardening accounts before anything goes wrong, our [account security service](https://www.awarexone.com/services/account-security) sets up 2FA, recovery details and device hygiene with you. [How we work and what we never ask for](https://www.awarexone.com/trust) is published, including that we never need your password or codes.

> Note: **The platform makes the final decision.** Only Meta can restore an Instagram or Facebook account, and only TikTok can restore a TikTok account. Good 2FA makes recovery far more likely, but nobody outside the platform can promise an outcome.

## Frequently Asked Questions

### Is SMS two-factor authentication better than nothing?

Yes. SMS 2FA stops anyone who only has your password. CISA's guidance still says any MFA beats none. But SMS codes can be caught through a SIM swap or a reissued number, and typed into fake pages, so use an authenticator app or passkey as your main method and keep SMS as a backup.

### Which authenticator app should I use for Instagram, Facebook and TikTok?

Any standard authenticator app that makes six-digit time-based codes will work. Instagram's help page mentions Duo Mobile and Google Authenticator, and TikTok's mentions Google Authenticator and Microsoft Authenticator. One app can hold codes for all three platforms. Choose one that can back up or transfer your accounts to a new phone.

### Does a passkey replace two-factor authentication?

Not on Meta or TikTok at the time of writing. A passkey is a phishing-resistant way to log in with your device's screen lock, offered alongside 2FA. Add a passkey where you see the option and keep 2FA switched on, so the account stays protected when you log in with a password on another device.

### I had 2FA turned on and still got hacked. How?

Most often a fake login page captured your password and code together, someone persuaded you to share a code, or malware copied your logged-in session so no code was needed. Change your password from inside the app, log out of all devices, get new backup codes, and check that the email and phone on the account are still yours.

### What happens to my 2FA when I change phones?

If you prepare, nothing. Move your authenticator app or its backup to the new phone before you wipe the old one, then test a login. If you forget, you will need a backup code, a second method or a logged-in device to get back in. Keep backup codes offline so a phone change never becomes a lockout.

### Should I tap "Trust this device" when I log in?

Only on your own phone or computer that nobody else uses. A trusted device skips the 2FA code on future logins, which is convenient but means anyone holding that device skips it too. Never trust a shared family tablet, an office computer or a public device, and remove old devices from your login activity list.

### Does WhatsApp 2FA on Instagram protect me from a SIM swap?

Not much. Instagram requires text message 2FA to be turned on before WhatsApp can be added, and both are linked to the same phone number. If an attacker takes over the number, both methods are at risk. Treat WhatsApp codes as a backup and use an authenticator app or passkey as your main method.

### Will Meta or TikTok ever ask me to send them a login code?

Treat any such request as a scam. Login codes and backup codes are only for the login screen you opened yourself. Messages claiming to be from support that ask for a code, a password or your backup codes are attempts to take the account. AwareXone will never ask for them either.

### Can I set up 2FA for a business Page or TikTok Shop the same way?

Each person with access needs 2FA on their own login, because a business asset is only as secure as its least-protected admin. Set it up for every admin using the steps above, keep two trusted people with full access, and remove anyone who leaves on their last day.

## Official sources

- [Instagram Help Center: Securing your Meta Account with two-factor authentication (accessed 28 September 2026)](https://help.instagram.com/566810106808145)
- [Instagram Help Center: How you can use a backup code on Instagram (accessed 28 September 2026)](https://help.instagram.com/1006568999411025)
- [Instagram Help Center: View your Instagram account's recent login activity (accessed 28 September 2026)](https://help.instagram.com/2761108904184084/)
- [Facebook Help Center: How two-factor authentication works on Facebook (accessed 28 September 2026)](https://www.facebook.com/help/148233965247823)
- [Facebook Help Center: Set up Facebook login recovery codes (accessed 28 September 2026)](https://www.facebook.com/help/148104135383285)
- [Facebook Help Center: How security keys work on Facebook (accessed 28 September 2026)](https://www.facebook.com/help/401566786855239)
- [Facebook Help Center: Create a passkey on Facebook (accessed 28 September 2026)](https://www.facebook.com/help/1181045243159511)
- [Facebook Help Center: Protect your account from malicious software designed to steal your login information (accessed 28 September 2026)](https://www.facebook.com/help/773912954219636)
- [Meta Help Center: Account settings you will be able to manage in Accounts Center (accessed 28 September 2026)](https://www.meta.com/help/accounts-center/841741830388205/)
- [Facebook Help Center: How Facebook uses your Accounts Center contact information for security notifications (accessed 28 September 2026)](https://www.facebook.com/help/1200773850272982)
- [Meta Help Center: About Meta passkeys (accessed 28 September 2026)](https://www.meta.com/help/meta-account/1991801474748071/)
- [TikTok Support: Account safety, security checkup and 2-step verification (accessed 28 September 2026)](https://www.tiktok.com/support/faq_detail?id=7543604780950624824)
- [TikTok Support: Account safety (accessed 28 September 2026)](https://support.tiktok.com/en/safety-hc/account-and-user-safety/account-safety)
- [Google Account Help: Turn on 2-Step Verification (accessed 28 September 2026)](https://support.google.com/accounts/answer/185839)
- [CISA: Implementing Phishing-Resistant MFA, fact sheet (October 2022)](https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf)
- [CISA: Cross-Sector Cybersecurity Performance Goals 2.0, goal 3.F (December 2025)](https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0)
- [The Edge Malaysia: Over 70% of active phone numbers on prepaid plans, says Fahmi (24 October 2023)](https://theedgemalaysia.com/node/687380)

---

AwareXone is an independent Malaysia-based provider, not affiliated with any platform. The platform makes the final decision on every account. AwareXone never asks for passwords, OTP codes, backup codes or session cookies.
