Our social accounts hold private conversations, photos, contacts, and sometimes access to other services. A stolen password can let someone impersonate you, scam your contacts, or lock you out. Multi-factor authentication (MFA)—also called two-factor authentication or 2-step verification—adds another check at sign-in. This guide explains three common choices and walks through the security settings for WhatsApp, Facebook, Instagram, and Telegram. Menu names and available options can change by app version, device, country, or account.
What MFA does—and why it matters
With password-only sign-in, a person who gets your password may be able to enter your account. MFA asks for an additional proof, such as a code from your phone or a cryptographic passkey. This can make a leaked or reused password less useful and can alert you to an unexpected sign-in. It is not a guarantee: phishing, a compromised device, weak account recovery, or a tricked user can still put an account at risk.
The three familiar factor types are something you know (a password or PIN), something you have (a phone or security key), and something you are (a biometric check on your device). MFA combines independent proof; two passwords are not two different factors.
Three sign-in methods: passkey, authenticator app, and SMS
1. Passkeys: strongest everyday option when available
A passkey uses a cryptographic credential tied to the real website or app. You approve sign-in with your device screen lock, such as a fingerprint, face unlock, or PIN; the biometric itself is not sent to the service. Because the credential is bound to the genuine service, a look-alike phishing page generally cannot use it. Depending on the service, a passkey may replace a password, provide an additional sign-in factor, or be offered only for certain sign-in or recovery steps. It is not the same thing as adding a fingerprint to an ordinary password.
How to set one up: open the service's official app or type its official website yourself; go to Security or Password and security; choose Passkeys if the option is offered; confirm your identity; and save the passkey in the trusted password manager or device account you use. Never create one on a public or shared device. Keep a second trusted device or another recovery method, and make sure you can access your passkey manager if your phone is lost. Only approve a passkey prompt you started.
2. Authenticator app: a strong broadly supported backup
An authenticator app generates a short, changing code on a device you control. It usually works without mobile reception. It is generally a better choice than SMS when passkeys are not available, but a real-time phishing site can still trick you into entering a code. Protect the phone and the authenticator app, and check whether its backup or sync feature is enabled and secured.
How to set one up: in the account's Two-factor authentication or 2-step verification menu, choose Authentication app; open your authenticator and scan the QR code (or enter the setup key manually); type the current code back into the service to confirm; then save the service's recovery codes somewhere private. If you change or reset your phone, follow the service's transfer process before erasing the old device. Do not share the QR code, setup key, or one-time code with anyone.
3. SMS code: better than password-only, but not the first choice
A service texts a sign-in code to your phone number. It is easy to set up and may be preferable to having no second step, but the number can be targeted through SIM-swap or number-transfer scams, and a code can be phished. Use an authenticator app or passkey instead when the service supports one. Never tell a caller or message sender your code—even if they claim to be support, a friend, or the app itself. A legitimate support agent should not need your one-time sign-in code.
Before you change account settings
- Secure the email account and phone number used for recovery first. Give the email a unique password and MFA; otherwise an attacker may use it to reset your social account.
- Update the app from its official app store. Use the real app or type the service's address yourself; do not follow security links from unexpected texts or DMs.
- Use a different, long password for every account. A password manager can generate and store them.
- Keep recovery codes offline or in a secure password manager. Treat them like passwords: anyone with a code may be able to access your account. Never post them or send them in a chat.
Facebook: enable two-factor authentication
In the Facebook app, open Menu or your profile picture, then Settings & privacy > Settings > Accounts Center > Password and security > Two-factor authentication. Select your Facebook account, choose an offered method (authenticator app, text message, or security key), and follow the confirmation prompts. In a browser, profile picture > Settings & privacy > Settings usually leads to Accounts Center. Meta also offers passkeys for eligible accounts/devices: look under Accounts Center > Password and security > Passkey. Availability and labels can vary. Save any recovery codes offered, and review Where you're logged in to remove devices you do not recognize.
Instagram: protect the account through Accounts Center
In Instagram, open your profile > menu > Accounts Center > Password and security > Two-factor authentication. Choose the Instagram account, select an available method, and complete the setup. Prefer an authenticator app or a passkey if your account offers it; use SMS rather than leaving the account unprotected if stronger methods are unavailable. Store backup codes safely, review active sessions, and secure any linked Facebook and email accounts too. If the menus differ, search the app's own Settings for Two-factor authentication rather than using a link sent to you.
WhatsApp: turn on Two-step verification and secure re-registration
WhatsApp's built-in Two-step verification is a PIN you create in addition to the SMS or call code used to register your phone number. It is not the same as an authenticator-app code. Open WhatsApp > Settings (on some phones, Menu) > Account > Two-step verification > Turn on. Create a PIN you do not use elsewhere, add an email address you can access, and confirm it. The email helps with recovery if you forget the PIN, so secure that mailbox with its own unique password and MFA. Menu names can differ slightly on Android and iPhone.
If WhatsApp shows a Passkeys option under Account, you can register a passkey for the sign-in or re-registration flow supported by your app. This is separate from the WhatsApp two-step PIN: keep Two-step verification enabled as well, and follow the current in-app instructions. Never share a WhatsApp registration code or your two-step PIN. Turn on security notifications if available, and periodically check Linked devices and log out anything you do not recognize.
Telegram: add its Two-Step Verification password
Telegram's Two-Step Verification adds a password after the login code when you sign in on a new device. In Telegram, open Settings > Privacy and Security > Two-Step Verification; create a strong password and add a recovery email if offered. Secure that email account too. Telegram may deliver login codes inside an already signed-in Telegram session rather than by SMS, so never forward a code or approve a login you did not start. Open Settings > Devices (or Active Sessions) and terminate sessions you do not recognize. This Telegram password is its own two-step method; do not assume an authenticator app or passkey is available unless your current official app explicitly offers it.
After setup: check recovery and active sessions
Sign out of unknown devices and remove old phone numbers, email addresses, and authentication methods you no longer control. Keep your phone's screen lock enabled, update its operating system, and set a carrier account PIN or port-out protection if your mobile provider offers it. Do not approve an unexpected login prompt. If you receive an MFA request you did not initiate, deny it, change your password from the official app/site, and check active sessions and recovery details.
If you think an account was taken over
Use the platform's official account-recovery page from a device you trust. Secure the email account and phone number tied to it, change reused passwords on other services, revoke unfamiliar sessions, and check that recovery email, phone, passkey, and MFA methods were not replaced. Warn contacts not to trust urgent money requests or suspicious links from the account. Do not pay an account-recovery stranger or share your codes; use only the service's official support and recovery instructions.
A 15-minute action plan
- Start with your main email account, because it can reset many other accounts.
- Turn on the strongest sign-in method available for Facebook and Instagram in Accounts Center.
- Enable WhatsApp Two-step verification and add a protected recovery email.
- Set Telegram Two-Step Verification and remove unknown active sessions.
- Save recovery codes, then review logged-in devices on every platform.
Best practical order: use a passkey where the service supports it; otherwise choose an authenticator app. Keep recovery methods current. If only SMS is available, turn it on rather than relying on a password alone—and never share a sign-in code.
Official sources and further reading
Meta: Two-factor authentication · Meta: Passkeys · WhatsApp: Two-step verification · Telegram FAQ: Two-Step Verification · CISA: Multi-Factor Authentication · NIST SP 800-63B
Security features and menu labels change. These steps were checked against platform help information on October 7, 2026; check each official app's current instructions before making changes. This is general education, not a guarantee against account compromise.