With 2-Step Verification, also called two-factor authentication, you can add an extra layer of security to your account in case your password is stolen. After you set up 2-Step Verification, you can sign in to your account with:
- Your password
- Your phone
Allow 2-Step Verification
- Open your Google Account.
- In the navigation panel, select Security.
- Under “Signing in to Google,” select 2-Step Verification Get started.
- Follow the on-screen steps.
Tip: If you use an account through your work, school, or other group, these steps might not work. If you can’t set up 2-Step Verification, contact your administrator for help.
After you turn on 2-Step Verification, you must complete a second step to verify it’s you when you sign in. To help protect your account, Google will ask that you complete a specific second step.
Use Google prompts
We recommend you sign in with Google prompts. They’re easier to enter than a verification code and can help protect against SIM swap and other phone number-based hacks.
Google prompts are push notifications you get on iPhones that are signed in to your Google Account with the Smart Lock app , Gmail app , or Google app . If you sign in to another compatible phone, you automatically get Google prompts on that device, until you sign out.
Based on the device and location info in the notification, you can:
- Tap Yes to allow sign-in.
- Tap No to block sign-in.
You can set up other verification methods in case you:
- Want increased protection against phishing
- Can’t get Google prompts
- Lose your phone
A physical security key is a small device that you can buy to help verify it’s you when you sign in. When we need to make sure it’s you, you can simply connect the key to your phone, tablet, or computer. Order your security keys.
To sign in to new devices, you may also use the security key built in to a compatible phone.
Tip: Security keys help protect your Google Account from phishing attacks, when a hacker tries to trick you into giving them your password or other personal information. Learn more about phishing attacks.
When you don't have an internet connection or mobile service, you can set up Google Authenticator or another app that creates one-time verification codes.
To help verify it's you, enter the verification code on the sign-in screen.