Two-factor authentication means logging into an account takes two separate proofs instead of one. The first is the password, something you know. The second is usually something you have, most often a six-digit code that appears on a phone, or a tap to approve on an authenticator app. A password alone gets nobody past the front door. Both, together, are required.

The reason this exists is that passwords fail constantly, and not always through carelessness. They get reused across sites, guessed from patterns, phished through fake login pages, or in one case that came up directly in a client’s own history, read aloud over a recorded phone call to someone posing as support. Two-factor does not stop the password from leaking. It stops the leaked password from being enough.

Why it matters to you

The accounts that matter most for a small business are usually not the flashy ones. It is the business Gmail account, because whoever controls it can reset the password on almost everything else: the ad account, the analytics, the domain registrar, the lead inbox. An account like that without two-factor is a single point of failure sitting in plain sight. Turning it on is one of the highest-value, lowest-effort security steps a business owner can take, and it is usually free.

It also matters because of who ends up holding super admin on these accounts. If the business is the super admin with two-factor turned on, nobody, including me, can get into that account without the business’s own phone in hand. That is the point.

How I set it up

Wherever accounts are created for a client, from Cloudflare down to the business email, I turn two-factor on as part of the setup and confirm it is working before I consider the work done. Where an account already existed before I got involved, I flag it as an outstanding item and walk the client through turning it on directly, because it usually takes a genuine, in-person step: opening an authenticator app or confirming a phone number, something only the account owner can complete.

I pair this with a password manager wherever it makes sense, because the two solve related but different problems. A password manager stops weak or reused passwords. Two-factor stops a leaked password from being enough on its own, even if it leaked somewhere completely outside my control.

What it looks like in practice

Logging in on a new device asks for a code from a phone, once. After that, most services remember the device for a stretch of weeks or months and skip the second step until something changes, like a new browser or a cleared cache. The friction is small and one-time. The protection covers every login after that, on every device that has not already been trusted.

Questions I get about this

Isn't a strong password enough on its own?
No. A password can be guessed, reused from another breach, or in one real case, read aloud on a recorded call. Two-factor means that even if a password leaks, whoever has it still cannot get in without the second proof, which they do not have.
Which accounts actually need this?
The ones that unlock everything else. A business Gmail or Google Workspace account is usually the key one, because whoever controls it can reset the passwords on Analytics, the ad account, the domain registrar and the lead inbox. That is the first account to lock down.
Is two-factor annoying to use day to day?
A little, the first time you log in on a new device. After that, most services remember the device for weeks or months, so it rarely comes up again.

Want this set up properly for your business?

This is the kind of thing I build every week. Grab a time and we will talk through what fits.