How to Set Up Two-Factor Authentication on Android

Updated September 2026 · three authenticator apps now carry their own dated listing figures, with how each one backs up in the table

A password is one lock. This adds the second, explains why a text message is the weakest version of it, and gets the codes onto a new phone without locking you out on the way.

Our answer
  • Move off SMS first because a SIM swap defeats it, and any authenticator app here is a stronger second factor than a text message.
  • Google Authenticator is the simplest starting point because its optional sync means a lost phone is not a lost account, on a listing read 3 September 2026 that is free with nothing sold inside, at 3.9 stars from 677,995 reviews.
  • Aegis is the pick if the second factor should never leave the phone because its vault is encrypted and its export is a file you keep, on a listing read 3 September 2026 that rates 4.7 stars from 6,215 reviews, the highest here.
  • Save the backup codes wherever you land because the lockout that actually happens is a lost phone with no codes written down.
Data checked: 3 September 2026. Verified against the Play Store listings on 3 September 2026 · full breakdown below.
How we verify. Every app here is checked against its own Google Play listing: rating and review count, the install band, price and the in-app purchase range, and the Contains ads label. How each app backs up, and what a passkey does, come from the developers' own documentation rather than from our own use of the apps. Ratings drift, so each figure carries the date it was read. Last full pass: 3 September 2026, repeated quarterly.

What 2FA actually is

Two-factor authentication means you prove who you are with two different things. The first is something you know, your password. The second is something you have, like a code from an app on your phone or a fingerprint tied to your device. Even if a thief has your password, they cannot finish signing in without that second factor.

You will see it called 2FA, two-step verification, or multi-factor authentication. The names differ but the idea is the same. The second factor can be a text message, a code from an authenticator app, a tap on a prompt sent to your phone, a physical security key, or a passkey. They are not equally safe, which is the part most guides skip.

Why SMS codes are the weakest option

Getting a code by text is better than no second factor at all. It is also the easiest one to defeat. The problem is called a SIM swap. An attacker contacts your mobile carrier, pretends to be you, and convinces them to move your number to a SIM card they control. From that moment, your calls and texts arrive on the attacker's phone, including every login code.

This is not rare. In 2024 the FBI's complaint center logged hundreds of SIM swap reports with losses above 26 million dollars, and both CISA and the FBI have told people to stop relying on SMS for sign-in security. A text code also travels across the carrier network, where it can be intercepted in other ways. A code from an authenticator app never leaves your phone and is not tied to your number at all, so a SIM swap does nothing.

If SMS is the only second factor an account offers, turn it on. But where you have the choice, use an app or a passkey instead, and treat SMS as a fallback rather than your main method.

Also on Best Apps for Android: Best Authenticator Apps for Android in 2026

Google Authenticator · the default, and its cloud backup

Simplest setup, codes that sync

3.9 stars from 677,995 reviews · 100,000,000+ installs · free to install · no in-app purchases listed · by Google LLC · Contains ads: No · checked 3 September 2026

Google Play listing · 3.9 (677,995) · read 3 September 2026

Google Authenticator is the one most guides assume: scan the QR code, and it produces a six digit code every 30 seconds without a network. Its optional Google account sync is what makes moving to a new phone survivable. It is free with nothing sold inside and no Contains ads label. The blunt con: at 3.9 stars from 677,995 reviews it is the lowest rated of the three here, and syncing codes to an account is a trade some people should not make.

  • Good: Codes are generated on the device, so they work with no signal at all
  • Good: Optional account sync means a lost phone is not a lost account
  • Good: No Contains ads label and no in-app purchases on its listing
  • Con: 3.9 stars from 677,995 reviews, the lowest of the three apps here
  • Con: Account sync puts your second factor in the same account it protects
  • Con: No app lock of its own on most setups: anyone past your screen lock sees the codes

Back to the comparison table

An authenticator app generates a fresh six-digit code every 30 seconds, based on a secret shared once between the app and the account. The code is calculated on your phone, so there is nothing to intercept. Google Authenticator is the obvious starting point on Android because it is free and works with almost every service, not just Google.

To install and use it:

  • Get Google Authenticator from Google Play. It needs Android 5.0 or later.
  • Open the account you want to protect (for example your Google account, a bank, or a social app) and find its security or two-step verification settings.
  • Choose to add an authenticator app. The service shows a QR code.
  • In Google Authenticator, tap the plus button and choose Scan a QR code, then point your camera at it.
  • The account appears in the app with a rotating code. Type the current code back into the service to confirm the link.

For your Google account specifically, open your Google Account, go to Security, then under how you sign in to Google pick 2-Step Verification and follow the steps to turn it on. You can add the authenticator from there.

Google Authenticator can now sync your codes to your Google account, so if you log in to the app on a new phone your codes come with you. Turn that on inside the app. It removes the old nightmare where a lost phone meant lost access. If you would rather keep everything offline, the sync is optional and you can leave it off. Authy and Microsoft Authenticator are solid alternatives if you prefer their backup approach, and they work the same way with the same QR codes.

One more setting worth using: the Privacy Screen option in Google Authenticator asks for your PIN, pattern, or fingerprint before the app will open, so a stranger holding your unlocked phone still cannot read your codes.

Aegis · encrypted, offline, and export you control

Keeping the second factor off the cloud

4.7 stars from 6,215 reviews · 500,000+ installs · free to install · no in-app purchases listed · by Beem Development · Contains ads: No · checked 3 September 2026

Google Play listing · 4.7 (6,215) · read 3 September 2026

Aegis is the pick if the point of a second factor is that it lives nowhere but your phone: the vault is encrypted behind its own password, and the export is a file you keep rather than a sync you trust. It is free with nothing sold inside and no Contains ads label, and at 4.7 stars it is the highest rated app on this page. The blunt con: a manual export is only a backup if you actually take one, and its audience is small at 6,215 reviews.

  • Good: The highest rated of the three at 4.7 stars, with no ads label and nothing sold
  • Good: The vault is encrypted behind its own password rather than the screen lock alone
  • Good: Export is an encrypted file you hold, so no cloud account is involved
  • Con: Backup is manual: no export, no recovery
  • Con: A small audience at 6,215 reviews and a 500,000+ install band
  • Con: Its listing has gone several months without an update

Back to the comparison table

Twilio Authy · multi device sync, at a price

Codes on a phone and a tablet at once

3.7 stars from 96,836 reviews · 10,000,000+ installs · free to install · no in-app purchases listed · by Twilio · Contains ads: No · checked 3 September 2026

Google Play listing · 3.7 (96,836) · read 3 September 2026

Authy is the one built around having your codes on more than one device, with encrypted backups tied to a phone number. It is free with nothing sold inside and no Contains ads label. The blunt con: at 3.7 stars from 96,836 reviews it is the lowest rated app on this page, and tying recovery to a phone number reintroduces exactly the SIM swap weakness this guide warns about in the SMS section.

  • Good: Codes on several devices at once, which no other app here does by default
  • Good: Encrypted backups, so a lost phone does not mean lost accounts
  • Good: No Contains ads label and no in-app purchases on its listing
  • Con: 3.7 stars from 96,836 reviews, the lowest on this page
  • Con: Recovery is tied to a phone number, the same channel a SIM swap attacks
  • Con: Multi device convenience widens the surface: more devices, more places to steal from

Back to the comparison table

Passkeys, the newer passwordless option

Passkeys are the direction sign-in is heading. Instead of a password plus a code, a passkey lets you sign in with the same fingerprint, face, or screen lock you already use to unlock your phone. Behind the scenes your device holds a private key that never leaves it, and the website only ever sees a matching public key. There is no shared secret to phish and no code to steal.

To create one for your Google account, go to your Google Account settings or visit the passkeys page, then follow the prompt to make a passkey. Your phone asks for your fingerprint, face, or PIN to confirm. You need Android 9 or later and a screen lock set. If you are already signed in on an Android phone, Google may have quietly created a passkey for you already.

Passkeys are stored in Google Password Manager and sync across your Android devices and Chrome browsers signed in to the same account. You can even sign in on a nearby laptop by approving it on your phone, without copying the passkey over. The honest limit: passkey support is still growing, so not every site offers it yet, and you usually keep an authenticator app or backup codes as your fallback. Think of passkeys as the better primary method, not a complete replacement yet.

Save your backup and recovery codes

This is the step people skip, and it is the step that saves you. When you turn on 2FA, most services offer a set of one-time backup codes. Google gives you ten. Each one works once to get past the second step if your phone is lost, dead, stolen, or reset.

Get your Google backup codes from the 2-Step Verification screen by choosing Backup codes, then download or print them. Where you put them matters:

  • Print them and keep the paper somewhere you keep important documents, away from your phone.
  • Or store them in a password manager, not in a plain notes file synced to the same account you are protecting.
  • Do not photograph them and leave the photo in your camera roll, and do not email them to yourself.

Each code dies after one use. If you run low or think they have been seen, open the same screen and refresh the set to invalidate the old ones. Treat these codes like a spare key to your house, because that is what they are.

Checklist showing five 2FA steps marked as recommended, avoid, or caution for Android users.
Quick checklist for setting up two-factor authentication on Android safely.

Move 2FA to a new phone without getting locked out

Changing phones is where most lockouts happen, because the second factor lives on the old device. Plan the move before you wipe or sell the old one.

If you use Google Authenticator with cloud sync on, the easy path is to install the app on the new phone and sign in to your Google account. Your codes appear automatically. If you keep sync off, transfer them manually: on the old phone open Authenticator, tap the menu, choose Transfer accounts, then Export accounts, and pick the accounts to move. It makes a QR code. On the new phone choose Transfer accounts, then Import accounts, and scan it.

For passkeys, signing in to the same Google account on the new Android phone brings them across through Google Password Manager. For accounts secured with non-Google authenticator apps, repeat the QR setup or use that app's own backup feature. Keep the old phone working until you have confirmed you can sign in to every account on the new one. Only then reset the old device.

The one mistake that locks people out

Here is the trap. People turn on 2FA, store the only second factor on one phone, never save backup codes, then lose, break, or factory-reset that phone. Now the account asks for a code that no longer exists anywhere, and the recovery process can take days or fail entirely.

Avoid it by always having a second way in before you need it. That means at least two of: cloud-synced authenticator codes, saved backup codes, a passkey on another device, or a registered recovery phone and email. Set them up the same day you turn on 2FA, not later. The whole point of 2FA is to keep attackers out, but it should never be the thing that keeps you out.

Keep reading

Questions, answered

Is SMS two-factor authentication still safe enough?

It is better than nothing and worse than everything else here. A SIM swap moves your number to an attacker's card, and the codes follow. Use it only where a service offers no other option. Checked 3 September 2026.

What happens to my 2FA if I lose my phone?

That depends entirely on what you set up in advance. Backup codes get you in; an app with sync or an export restores the codes; neither of those set up means the account recovery process, which can take days. Checked 3 September 2026.

Do you need to pay for an authenticator app?

No. All three apps here are free to install, list no in-app purchases and carry no Contains ads label, read 3 September 2026. Paying is not what separates them: how they back up is. Checked 3 September 2026.

Are passkeys replacing passwords and 2FA completely?

Gradually, and not yet everywhere. A passkey folds both factors into the device unlock you already use, but coverage is uneven, so most people run passkeys where they exist and an authenticator app everywhere else. Checked 3 September 2026.

Can one authenticator app hold many accounts?

Yes, and that is the normal setup: each account adds its own entry and its own rotating code. It also means one phone holds many keys, which is why the backup question matters more than the app choice. Checked 3 September 2026.

Where should you store my backup codes?

Somewhere that survives losing the phone and is not inside the account they protect. A password manager on another device, or printed and kept with your documents. Not a screenshot in the photo library that syncs to the same account. Checked 3 September 2026.

Checked 3 September 2026: the guide recommended an authenticator app without naming a single one in a way a reader could act on, with no store link, no rating and no dated line. Three now carry a fact line read from their own listing, a store link, a decision table row with how each one backs up, and three pros and three cons. The figures reorder the advice: Aegis rates 4.7 stars, Google Authenticator 3.9 and Authy 3.7, and Authy ties recovery to a phone number, which is the same channel the SMS section of this page warns about.

Set Up Two-Factor Authentication on Android: Apps and Backups