Set up 2-Step Verification

Protect your business with 2-Step Verification

These articles are for Google Workspace administrators. Google Workspace users should go to Turn on 2-Step Verification

You can use 2-Step Verification (2SV) to put an extra barrier between your business and cybercriminals who try to steal usernames and passwords to access business data.

Important: 2SV soon required for admin accounts

To better protect your organization’s information, Google will soon require all administrator accounts to have 2SV enabled. Enforcement will begin with Enterprise editions and will progressively expand to all Google Workspace editions throughout 2024. It is recommended that you enable 2SV for your admins prior to Google enforcing it. Be aware that:

  • Enforcement is rolling out over the next year. Super administrators will get a notification 30 days before enforcement.
  • You can review an admin's enforcement status in the Google Admin console. For the steps, go to Track users’ enrollment and add the 2-Step verification enforcement column.
  • If you make a user an admin, enforcement is immediately applied.
  • When an admin signs in to their account, they’re reminded to enable 2SV by the mandatory date. 
  • If an admin can't sign in after 2SV enforcement, follow the steps to recover an administrator account.

What is 2-Step Verification?

With 2SV, your users sign in to their account in two steps with something they know (their password) and something they have (their phone or a  Security Key). Learn how it works

Secure your Google Workspace user accounts

Do small businesses need 2-Step Verification?

Cybercriminals target businesses of all sizes. If a hacker gets into your administrator account, they can see your email, documents, spreadsheets, financial records, and more.

A hacker could steal or guess a password, but they can’t reproduce something only you have.

2-Step Verification methods

When you set up 2-Step Verification, you choose the second verification step for your users.

Open all  |   Close all

Security keys
""Security keys are the most secure form of 2-Step Verification and protect against phishing threats. Types of security keys:

When a user signs in to their Google Account, their device detects that the account has a security key. For the second verification step, the user signs in with their security key. Users connect their security key to their device by USB, Bluetooth, or NFC (Near Field Communication), depending on the type of key. Learn more about security keys

Google prompt
""Users can set up their Android or Apple mobile devices to receive a sign-in prompt. When they sign in to their Google Account on their computer, they get a "Trying to sign in?" prompt on their mobile device. They simply confirm by tapping their mobile device. Signing in this way adds the security of 2-Step Verification and is quicker than entering a verification code. Learn more about phone prompts
Google Authenticator and other verification code generators
"" Users generate one-time verification codes on a hardware token (small hardware device) or an app on their mobile device, such as Google Authenticator. The user enters the code to sign in to their computer and other devices, including the mobile device itself. Google Authenticator and other apps don't need an internet connection to generate codes.
2-Step Verification supports software and hardware tokens that use the TOTP (Time-based One Time Password) standard.
Backup codes
""If a user doesn't have their mobile device or works in an area where they can't carry mobile devices, they can use backup codes for 2-Step Verification. Users can generate backup verification codes and print them ahead of time.
Text message or phone call
""Google sends a 2-Step Verification code to mobile devices in a text message or voice call.
 

Note: 2-step verification using local phone numbers is not currently supported for some domains in Nigeria and Ivory Coast, due to large volumes of account abuse in those countries. For information on whether your domain is eligible, please contact Support.

Best practices for 2-Step Verification

Enforce 2-Step Verification for administrators and key users
You can make 2-Step Verification optional or required for your users. We recommend enforcing 2-Step Verification for your administrator account and users who work with your most important business information.
  • The administrator account is the most powerful account because it can delete users, reset passwords, and access all your data.
  • Users who work with sensitive data such as financial records and employee information should also use 2-Step Verification.
Consider using security keys in your business
Because security keys are the strongest 2-Step Verification method, consider using them in your business.
  • Security keys—The strongest 2-Step Verification method, and they don’t require users to enter codes. You can buy compatible security keys from a retailer you trust, or Titan Security Keys from the Google Store. Or your users can use their phone's built-in security key (available on phones running Android 7+ or iOS 10+).
  • Alternatives to security keys—If you decide not to use security keys, Google prompt or the Google Authenticator app are good alternatives. Google prompt provides a better user experience because users simply tap their device when prompted instead of entering a verification code.
  • Text messages are discouraged—They rely on external carrier networks and might be intercepted.

What's next?

Was this helpful?

How can we improve it?
Search
Clear search
Close search
Google apps
Main menu
8892895024779993183
true
Search Help Center
true
true
true
true
true
73010