Turn it on
Open Settings, then Account, then Security, and find the Two-step verification card. It is opt-in, per person: you turn it on for your own sign-in, not for the whole workspace.
Choose how the code reaches you:
- Authenticator app. Scan a QR code, or copy the setup key into 1Password, Google Authenticator or Apple Passwords, then confirm with a six-digit code.
- Text message. Enter a mobile number, verify it by text, and codes arrive there. If a text cannot be delivered, the code falls back to your email so you are not locked out by a carrier hiccup.
- Email code. Codes arrive at the account’s email address.
You confirm your password on the way in, and enrollment always ends with a code round-trip, so you cannot turn it on with a method that does not actually reach you.
Change method and Turn off live on the same card.
Every door gets the same lock
Signing in with Google or Apple is challenged the same way as signing in with a password. A second step that only guarded one of your sign-in methods would not be a second step.
You can choose trust this device for 30 days at the challenge, so your own machine does not ask you every morning.
Passkeys
The Passkeys card sits beside two-step verification, and the two are related but not the same thing.
A passkey replaces the password on devices that support it, and a passkey sign-in is not asked for a second step: the passkey lives in your device and unlocks with your face, fingerprint or device PIN, so it already is two factors. If you have a passkey enrolled, the sign-in challenge offers it first.
If you lose access
There are no backup codes to print and lose. If you cannot receive codes any more, contact support and we will verify you and recover the account.
A lost phone
Sign out on all devices, on the same Security page, cuts every signed-in session loose at once. Use it the day a phone goes missing, then change your password.