window.nitroFragments['07d379ca8ea2f696399a9d53582b1d5e'] = {"isLazyLoaded":true,"content":"<div class="container_wrap container_wrap_first main_color sidebar_right nitro-lazy-render" nitro-fragment-parent> <div class='container template-blog template-single-blog'> <main class='content units av-content-small alpha  av-blog-meta-comments-disabled av-blog-meta-tag-disabled av-main-single'> <div class="table-content"><div class='table-of-contents'><span class='toc-headline'>Table Of Contents</span><span class='toggle-toc custom-setting' title='collapse'>−</span><ul><li><a href="#what-is-about-two-factor-authentication">What is About Two-factor authentication?</a></li><li><a href="#simplify-two-factor-authentication-with-powerdmarc">Simplify Two-Factor Authentication with PowerDMARC!</a></li><li><a href="#how-two-factor-authentication-2fa-works">How Two-Factor Authentication (2FA) Works</a></li><li><a href="#common-2fa-methods">Common 2FA Methods</a></li><li><a href="#enabling-multi-factor-authentication-on-different-platforms">Enabling Multi-Factor Authentication on Different Platforms</a><ul><li><a href="#enabling-two-factor-authentication-for-gmail-google-workspace-emails">Enabling Two-factor authentication for Gmail Google Workspace Emails&nbsp;</a><ul><li><a href="#step-1-open-the-two-step-verification-page">Step 1: Open the two-step verification page</a></li><li><a href="#step-2-choose-a-verification-method">Step 2: Choose a verification method</a></li><li><a href="#step-3-set-up-phone-verification-text-call">Step 3: Set up phone verification (Text/Call)</a></li><li><a href="#step-4-complete-the-verification-process">Step 4: Complete the verification process</a></li><li><a href="#step-5-turn-on-2-factor-authentication">Step 5: Turn on 2-factor authentication</a></li><li><a href="#step-6-set-up-google-prompts">Step 6: Set up Google prompts</a></li><li><a href="#step-7-use-a-security-key">Step 7: Use a security key</a></li></ul></li><li><a href="#how-to-turn-off-2fa-for-gmail">How to turn off 2FA for Gmail</a></li><li><a href="#setting-up-gmail-2fa-on-android-or-ios-devices">Setting up Gmail 2FA on Android or iOS devices</a><ul><li><a href="#step-1-access-google-account-settings">Step 1: Access Google Account settings</a></li><li><a href="#step-2-navigate-to-security-settings">Step 2: Navigate to Security settings</a></li><li><a href="#step-3-follow-setup-prompts">Step 3: Follow setup prompts</a></li><li><a href="#step-4-enter-verification-code">Step 4: Enter verification code</a></li><li><a href="#step-5-turn-on-2fa">Step 5: Turn on 2FA</a></li></ul></li><li><a href="#how-to-set-up-email-multi-factor-authentication-for-microsoft-365">How to set up Email Multi-Factor Authentication for Microsoft 365</a></li><li><a href="#how-to-set-up-email-multi-factor-authentication-for-zoho-mail">How to set up Email Multi-Factor Authentication for Zoho Mail</a></li><li><a href="#google-authenticator">Google Authenticator</a></li></ul></li><li><a href="#benefits-of-2fa-mfa">Benefits of 2FA/MFA</a></li><li><a href="#downsides-of-2fa-mfa">Downsides of 2FA/MFA</a></li><li><a href="#importance-of-email-security">Importance of Email security</a></li><li><a href="#conclusion">Conclusion</a></li></ul></div></div><article class="post-entry post-entry-type-standard post-entry-56735 post-loop-1 post-parity-odd post-entry-last single-big with-slider post-56735 post type-post status-publish format-standard has-post-thumbnail hentry category-blogs"><div class="blog-meta"></div><div class='entry-content-wrapper clearfix standard-content'><header class="entry-content-header" aria-label="Post: How to Turn on Two-Factor Authentication for Emails?"><div class="av-heading-wrapper"></div></header><span class="av-vertical-delimiter"></span><div class="entry-content"><p><span style="font-weight:400;">Email has been one of the most widely used ways of sharing data among professionals. Therefore, hackers have also become experts at retrieving data by breaching email security. The problem arises when companies don’t pay much attention to updating their email security methods and end up getting scammed. Email multi-factor authentication is a method of authenticating a user using more than one method. It&#8217;s commonly used to secure online <a id="link_juicer" href="https://powerdmarc.com/cyber-security-in-banking/" data-wpel-link="internal" target="_self" rel="follow">banking</a> and other financial transactions but is also helpful for anything that needs a secure connection that can&#8217;t be accessed by just your password alone.</span></p> <p><span style="font-weight:400;">As recorded by the </span><a href="https://www.ic3.gov/Media/PDF/AnnualReport/2020_IC3Report.pdf" rel="nofollow noopener" data-wpel-link="external" target="_blank"><span style="font-weight:400;">Internet Crime Report</span></a><span style="font-weight:400;">, in 2020, there were 19,369 complaints about the Business Email Compromise (BEC). It resulted in adjusted losses exceeding $1.8 billion.</span></p> <p><span style="font-weight:400;">Two-factor authentication is built to make email accounts secure by adding a layer of security over username and password. The second layer of security can be anything like a fingerprint, a code, or a security token. There are several different types of multi-factor authentication systems out there—some use two-factor authentication while others deploy a multilayered approach towards sender verification—but they all have one thing in common: they&#8217;re designed to make sure that only authorized users can access the service they&#8217;re trying to provide.</span></p> <p><span style="font-weight:400;">Here’s a guide on how to set up Two-factor <a id="link_juicer" href="https://powerdmarc.com/what-is-email-authentication/" data-wpel-link="internal" target="_self" rel="follow">authentication for emails</a> and why it is important to make your accounts secure.</span></p> <p></p> <div style="background:white;border:1px solid #ddd;border-radius:8px;box-shadow:2px 2px 10px rgba(0,0,0,.1);padding:20px 30px 20px 20px;max-width:600px;margin:20px auto;"> <p style="font-size:20px;font-weight:bold;margin-bottom:10px;">Key Takeaways</p> <ol style="padding-left:20px;margin-right:10px;"> <li>Email security is paramount due to evolving threats like Business Email Compromise (BEC), costing billions annually.</li> <li>Multi-Factor Authentication (MFA), including Two-Factor Authentication (2FA), significantly boosts security by requiring multiple verification factors (e.g., something you know, something you have, something you are).</li> <li>Common MFA/2FA methods include SMS codes, authenticator apps (like Google Authenticator), biometrics, and hardware tokens, offering varied security and convenience.</li> <li>Implementing MFA/2FA is crucial across major platforms like Gmail, Microsoft 365, and Zoho Mail, with specific setup steps available for each.</li> <li>Combining MFA/2FA with email authentication protocols like DMARC provides comprehensive protection against unauthorized access, phishing, and <a id="link_juicer" href="https://powerdmarc.com/what-is-domain-impersonation/" data-wpel-link="internal" target="_self" rel="follow">domain spoofing</a>.</li> </ol> </div> <h2 id="what-is-about-two-factor-authentication"><span style="font-weight:400;">What is About Two-factor authentication?</span></h2> <p><span style="font-weight:400;">Multi-factor authentication (MFA) is a security measure that requires more than just a password to access a device or system, verifying a user&#8217;s identity with two or more different forms of identification. Two-factor authentication (2FA) is a specific type of MFA, an email security method that requires users to provide two different authentication factors to verify their identity. It&#8217;s used to enhance email security in addition to a strong password. It adds a randomly generated code to the login process, which you have to add every time before logging in to your account. In most cases, this includes something physical, like a phone number or fingerprint scan (something you have or are), but it can also include something digital, like a token that stores information on an app on your phone (like Google Authenticator). It&#8217;s also used for authentication in situations where the user&#8217;s password is compromised, such as through phishing attacks.</span></p> <p><span style="font-weight:400;">Once the code is activated, you can access your email accounts by entering this. This dual-factor authentication protects your associated email accounts as well as other applications. Even if someone else gets to know your password, they can’t log in without the code.</span></p> <h2 style="text-align:center;" id="simplify-two-factor-authentication-with-powerdmarc"><strong>Simplify Two-Factor Authentication with PowerDMARC!</strong></h2> <div class='avia-buttonrow-wrap av-tpjcrs-b04d460599174e0c7f2fe8361f9c0ec5 avia-buttonrow-center  avia-builder-el-0  avia-builder-el-no-sibling'> <a href="https://app.powerdmarc.com/en/members/register" class="avia-button av-m2nbzt8f-920d527a12282367b206ba6e64d16fae avia-icon_select-no avia-size-x-large avia-color-black" aria-label="Start 15-day trial" data-wpel-link="external" target="_blank"><span class='avia_iconbox_title'>Start 15-day trial</span></a> <a href="https://powerdmarc.com/book-a-demo/" class="avia-button av-m2nbzt8f-2-828d32fdd5277c82d1e479ee3d6511da avia-icon_select-no avia-size-x-large avia-color-blue" aria-label="Book a demo" data-wpel-link="internal" target="_self" rel="follow"><span class='avia_iconbox_title'>Book a demo</span></a> </div> <h2 id="how-two-factor-authentication-2fa-works"><span style="font-weight:400;">How Two-Factor Authentication (2FA) Works</span></h2> <p><span style="font-weight:400;">Here is how 2FA typically works:</span></p> <ol> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">The first thing you need to do is to enter your username and password. It is the most common form of authentication. It involves something the user knows.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">After the username and password are entered and verified, the system will request a second factor. This is usually something the user has (such as a phone receiving a text message or push notification, or a hardware token) or something the user is (like a fingerprint or face scan).</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Choose the method that seems most appropriate. Then enter the code from your phone, hardware token, or approve the push notification. If both the password and the second factor are correct, the system grants access to the user. In most cases, you&#8217;ll need to use two different forms of verification to complete the signup or login.</span></li> </ol> <h2 id="common-2fa-methods"><span style="font-weight:400;">Common 2FA Methods</span></h2> <p><img alt="" width="600" height="357" title="How to Turn on Two-Factor Authentication for Emails?" sizes="(max-width: 600px) 100vw, 600px" nitro-lazy-srcset="https://cdn-caklk.nitrocdn.com/sJCpruYkVvovUsWvtAEzkQwTuXjDDQLL/assets/images/optimized/rev-fb8e741/powerdmarc.com/wp-content/uploads/2024/05/Common-2FA-Methods.png 865w, https://cdn-caklk.nitrocdn.com/sJCpruYkVvovUsWvtAEzkQwTuXjDDQLL/assets/images/optimized/rev-fb8e741/powerdmarc.com/wp-content/uploads/2024/05/Common-2FA-Methods-300x178.png 300w, https://cdn-caklk.nitrocdn.com/sJCpruYkVvovUsWvtAEzkQwTuXjDDQLL/assets/images/optimized/rev-fb8e741/powerdmarc.com/wp-content/uploads/2024/05/Common-2FA-Methods-768x456.png 768w, https://cdn-caklk.nitrocdn.com/sJCpruYkVvovUsWvtAEzkQwTuXjDDQLL/assets/images/optimized/rev-fb8e741/powerdmarc.com/wp-content/uploads/2024/05/Common-2FA-Methods-705x419.png 705w" nitro-lazy-src="https://cdn-caklk.nitrocdn.com/sJCpruYkVvovUsWvtAEzkQwTuXjDDQLL/assets/images/optimized/rev-fb8e741/powerdmarc.com/wp-content/uploads/2024/05/Common-2FA-Methods.png" class="alignnone wp-image-56740 nitro-lazy" decoding="async" nitro-lazy-empty id="MTM2ODo2MjA=-1" src="data:image/svg+xml;nitro-empty-id=MTM2ODo2MjA=-1;base64,PHN2ZyB2aWV3Qm94PSIwIDAgODY1IDUxNCIgd2lkdGg9Ijg2NSIgaGVpZ2h0PSI1MTQiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyI+PC9zdmc+" /></p> <p><span style="font-weight:400;">Here are some common methods used for 2FA:</span><b></b></p> <ul> <li aria-level="1"><strong>SMS Text Message:</strong><span style="font-weight:400;"> A code is sent to your phone via text message.</span></li> </ul> <ul> <li aria-level="1"><strong>Authentication App:</strong><span style="font-weight:400;"> Apps like Google Authenticator generate a code that changes every few seconds.</span></li> </ul> <ul> <li aria-level="1"><strong>Biometric Verification:</strong><span style="font-weight:400;"> This uses your fingerprint, face, or iris scan to verify your identity.</span></li> </ul> <ul> <li aria-level="1"><strong>Email Verification:</strong><span style="font-weight:400;"> A code is sent to your email address.</span></li> </ul> <ul> <li aria-level="1"><strong>Hardware Token:</strong><span style="font-weight:400;"> A small device generates a code you can use to log in.</span></li> </ul> <ul> <li aria-level="1"><strong>Push Notification:</strong><span style="font-weight:400;"> A notification is sent to your smartphone, and you approve the login by pressing a button.</span></li> </ul> <h2 id="enabling-multi-factor-authentication-on-different-platforms"><span style="font-weight:400;">Enabling Multi-Factor Authentication on Different Platforms</span></h2> <p><span style="font-weight:400;">Setting up MFA ensures that only authorized individuals can access your accounts. Below are guides for enabling it on popular platforms.</span></p> <h3 id="enabling-two-factor-authentication-for-gmail-google-workspace-emails"><span style="font-weight:400;">Enabling Two-factor authentication for Gmail Google Workspace Emails</span><b>&nbsp;</b></h3> <p><span style="font-weight:400;">Here is a simple yet thorough guide on </span><a href="https://support.google.com/accounts/answer/185839?hl=en&amp;co=GENIE.Platform%3DDesktop" rel="nofollow noopener" data-wpel-link="external" target="_blank"><span style="font-weight:400;">enabling 2FA</span></a><span style="font-weight:400;"> (also called 2-Step Verification by Google) for your Gmail accounts.</span></p> <h4 id="step-1-open-the-two-step-verification-page"><span style="font-weight:400;">Step 1: Open the two-step verification page</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Open a browser on your computer and navigate to the <a href="https://myaccount.google.com/signinoptions/two-step-verification/enroll-welcome" rel="nofollow noopener" data-wpel-link="external" target="_blank">two-step verification page</a>.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Sign in to your Google account.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Read the instructions given and click “Get Started” to proceed.</span></li> </ul> <h4 id="step-2-choose-a-verification-method"><span style="font-weight:400;">Step 2: Choose a verification method</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">You will see the options for setting up two-step verification in Gmail.</span></li> </ul> <p><span style="font-weight:400;">(Through text messages/phone calls, Google prompts, an authenticator app, or a security key)</span></p> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Google will typically suggest using Google prompts first if you have a compatible smartphone signed in.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Click on “Show more options” if you prefer a different method or want to set up additional methods.</span></li> </ul> <h4 id="step-3-set-up-phone-verification-text-call"><span style="font-weight:400;">Step 3: Set up phone verification (Text/Call)</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">If you choose verification via text message or phone call, you will get a six-digit code every time you log into your Gmail on a new device or after clearing cookies.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Enter your mobile phone number. Choose whether to get codes via text message or phone call. Click “Next”.</span></li> </ul> <h4 id="step-4-complete-the-verification-process"><span style="font-weight:400;">Step 4: Complete the verification process</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">You will get a code sent to your phone via the method selected.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Enter the received code and click “Next” again.</span></li> </ul> <h4 id="step-5-turn-on-2-factor-authentication"><span style="font-weight:400;">Step 5: Turn on 2-factor authentication</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">After successfully verifying your chosen method, you can activate the two-step verification process.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Click “Turn on” to activate it.</span></li> </ul> <h4 id="step-6-set-up-google-prompts"><span style="font-weight:400;">Step 6: Set up Google prompts</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Google prompts display an approval screen on your trusted smartphone or tablet when you sign in.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">If not set up initially, select “Google prompt” from the verification options.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Ensure you are signed in to your Google account on a compatible Android or iOS device (with the Google app or Gmail app installed). Google will automatically detect eligible devices. Follow the on-screen prompts to confirm.</span></li> </ul> <h4 id="step-7-use-a-security-key"><span style="font-weight:400;">Step 7: Use a security key</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">A security key is a physical device (USB, NFC, or Bluetooth) that provides strong authentication.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Select “Security Key” from the verification options (you might find it under &#8220;Show more options&#8221;).</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Click “Next” and follow the instructions to register your key by inserting it or bringing it near your device.</span></li> </ul> <p><span style="font-weight:400;">You can also set up the Google Authenticator app or backup codes as additional or alternative methods.</span></p> <h3 id="how-to-turn-off-2fa-for-gmail"><span style="font-weight:400;">How to turn off 2FA for Gmail</span></h3> <p><span style="font-weight:400;">To </span><a href="https://support.google.com/accounts/answer/1064203?hl=en&amp;co=GENIE.Platform%3DAndroid#:~:text=Manage%20your%20Google%20Account.,Tap%20Turn%20off." rel="nofollow noopener" data-wpel-link="external" target="_blank"><span style="font-weight:400;">turn off 2-Step Verification</span></a><span style="font-weight:400;"> for your Google account:</span></p> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Go to your <a href="https://myaccount.google.com/" rel="nofollow noopener" data-wpel-link="external" target="_blank">Google Account</a>.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">On the left navigation panel, select “Security”.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Under the section “How you sign in to Google”, find and select “2-Step Verification”. You might need to log in again here.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Select “Turn off”.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Confirm your choice by tapping “Turn off” again.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Destroy or delete any backup codes you have saved for this account to ensure they can’t be used.</span></li> </ul> <p><span style="font-weight:400;">These steps help ensure that 2FA is completely disabled, and all backup access methods are removed.</span></p> <h3 id="setting-up-gmail-2fa-on-android-or-ios-devices"><span style="font-weight:400;">Setting up Gmail 2FA on Android or iOS devices</span></h3> <p><span style="font-weight:400;">Setting up Two-factor authentication on </span><a href="https://support.google.com/accounts/answer/1066447?hl=en&amp;co=GENIE.Platform%3DiOS" rel="nofollow noopener" data-wpel-link="external" target="_blank"><span style="font-weight:400;">Android or iOS</span></a><span style="font-weight:400;"> is similar to the desktop process but initiated through device settings or the Gmail app.</span></p> <h4 id="step-1-access-google-account-settings"><span style="font-weight:400;">Step 1: Access Google Account settings</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">On Android: Go to Settings &gt; Google &gt; Manage your Google Account.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">On iOS: Open the Gmail app, tap your profile picture in the top-right corner, then tap “Manage your Google Account”. (Alternatively, use the Google app or visit myaccount.google.com in a browser).</span></li> </ul> <h4 id="step-2-navigate-to-security-settings"><span style="font-weight:400;">Step 2: Navigate to Security settings</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Swipe over or tap to the &#8220;Security&#8221; tab.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Scroll down to the “How you sign in to Google” section and tap &#8220;2-Step Verification&#8221;.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Tap “Get started”. You might be asked to sign in again.</span></li> </ul> <h4 id="step-3-follow-setup-prompts"><span style="font-weight:400;">Step 3: Follow setup prompts</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Google will likely suggest Google Prompts first, recognizing the device you&#8217;re using. Tap &#8220;Continue&#8221;.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">It will ask for a backup option. Provide your phone number and choose to receive codes via text or call. Tap &#8220;Send&#8221;.</span></li> </ul> <h4 id="step-4-enter-verification-code"><span style="font-weight:400;">Step 4: Enter verification code</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Enter the code sent to your phone and tap “Next”.</span></li> </ul> <h4 id="step-5-turn-on-2fa"><span style="font-weight:400;">Step 5: Turn on 2FA</span></h4> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Review the settings and tap “Turn On” to activate 2-Step Verification.</span></li> </ul> <p><span style="font-weight:400;">After turning it on, you can add other methods like Authenticator apps or security keys via the 2-Step Verification settings page.</span></p> <h3 id="how-to-set-up-email-multi-factor-authentication-for-microsoft-365"><span style="font-weight:400;">How to set up Email Multi-Factor Authentication for Microsoft 365</span></h3> <p><b>Step 1</b><span style="font-weight:400;">: Ensure you have the necessary administrative privileges (e.g., Global Administrator) to manage MFA settings.</span></p> <p><b>Step 2</b><span style="font-weight:400;">: Microsoft recommends using Security Defaults or Conditional Access policies instead of legacy per-user MFA. If enabling Security Defaults:</span></p> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Sign in to the <a href="https://admin.microsoft.com/" rel="nofollow noopener" data-wpel-link="external" target="_blank">Microsoft 365 admin center</a>.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Navigate to the Azure Active Directory admin center (You might find this under <b>Show all &gt; Admin centers &gt; Azure Active Directory</b>).</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">In the Azure AD admin center, select <b>Azure Active Directory &gt; Properties</b>.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Click on <b>Manage Security defaults</b>.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Set the &#8220;Enable Security defaults&#8221; toggle to <b>Yes</b>.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Click <b>Save</b>. (Note: This enables baseline security features, including MFA for admins and eventually all users).</span></li> </ul> <p><span style="font-weight:400;">Alternatively, for more granular control, use Conditional Access policies (requires Azure AD Premium P1 or P2 license).</span></p> <p><b>Step 3</b><span style="font-weight:400;">: If you were previously using per-user MFA and are switching to Security Defaults or Conditional Access, you may need to disable it first.</span></p> <ul> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">In the Microsoft 365 admin center, go to <b>Users &gt; Active users</b>.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Click on <b>Multi-factor authentication</b> near the top.</span></li> <li style="font-weight:400;" aria-level="1"><span style="font-weight:400;">Select users and change their MFA status to <b>Disabled</b> if necessary.</span></li> </ul> <p><b>Step 4</b><span style="font-weight:400;">: Users will be prompted to register for MFA upon their next sign-in after Security Defaults or relevant Conditional Access policies are enabled. They will typically use the Microsoft Authenticator app.</span></p> <h3 id="how-to-set-up-email-multi-factor-authentication-for-zoho-mail"><span style="font-weight:400;">How to set up Email Multi-Factor Authentication for Zoho Mail</span></h3> <p><b>Step 1</b><span style="font-weight:400;">: <a href="https://accounts.zoho.com/" rel="nofollow noopener" data-wpel-link="external" target="_blank">Login</a> to your Zoho account settings (accounts.zoho.com).</span></p> <p><b>Step 2</b><span style="font-weight:400;">: In the left-side menu, click on <b>Security</b>, then select <b>Multi-Factor Authentication</b>.</span></p> <p><b>Step 3</b><span style="font-weight:400;">: Choose your preferred MFA method. Options typically include:</span></p> <ul> <li><span style="font-weight:400;"><b>Zoho OneAuth App:</b> (Recommended) Download the app (available for iOS and Android). You can set it up for push notifications, QR code scanning, or time-based one-time passwords (TOTP). Follow the on-screen instructions to link the app to your account, often involving scanning a QR code.</span></li> <li><span style="font-weight:400;"><b>Authenticator App (TOTP):</b> Use other apps like Google Authenticator or Microsoft Authenticator. Select this option, scan the provided QR code with your chosen app, and enter the code displayed in the app to verify.</span></li> <li><span style="font-weight:400;"><b>SMS/Voice Call:</b> Enter your phone number and verify it with a code sent via SMS or call.</span></li> <li><span style="font-weight:400;"><b>Security Key (YubiKey):</b> Register a U2F/FIDO2 compliant hardware key.</span></li> </ul> <p><b>Step 4</b><span style="font-weight:400;">: Follow the specific setup instructions for your chosen method to activate it.</span></p> <p><b>Step 5</b><span style="font-weight:400;">: Zoho also provides backup verification codes and allows setting up trusted browsers to reduce the frequency of MFA prompts on familiar devices.</span></p> <h3 id="google-authenticator"><span style="font-weight:400;">Google Authenticator</span></h3> <p><span style="font-weight:400;">A mobile security application, named Google Authenticator, is used to enhance the protection of email apps and websites by Two-factor authentication. It generates random Time-based One-Time Passwords (TOTP) on the user’s mobile device. These codes provide a second layer of security for verification, enhancing the overall security.</span></p> <p><span style="font-weight:400;">Google Authenticator doesn’t rely on SMS or network connectivity after initial setup. It generates a time-based, one-time code that is locally stored on the user’s device for sign-in purposes. It works as a decentralized approach to reduce unauthorized access to the email account, especially compared to potentially interceptable SMS codes.</span></p> <h2 id="benefits-of-2fa-mfa"><span style="font-weight:400;">Benefits of 2FA/MFA</span></h2> <p><span style="font-weight:400;">The benefits of 2FA/MFA include:</span></p> <p><img alt="" width="600" height="222" title="How to Turn on Two-Factor Authentication for Emails\"}; window.dispatchEvent(new CustomEvent('nitrofragmentloaded', {detail: "07d379ca8ea2f696399a9d53582b1d5e"}));