To set up multi-factor authentication (MFA), first identify which account actually signs you in to the cloud console, then enroll an allowed second factor in that identity provider’s official security settings. Add and test a recovery option before relying on MFA. The steps differ for AWS, Google Cloud, and Microsoft work accounts, and an organization administrator may control which methods you can use.
Before enrolling, identify the account that signs you in
A cloud console may authenticate you with an account managed by the cloud provider, an organization-managed identity, or an external identity provider. The owner of that identity controls the enrollment flow and available factors. For a work or school account, find out whether sign-in is managed by AWS, Microsoft Entra, Google Workspace or Cloud Identity, or another federated provider. If you cannot tell, ask your administrator rather than changing settings on a different personal account.
If the account belongs to an organization, you may not be able to turn MFA on yourself. Microsoft requires an administrator to enable MFA before Microsoft 365 users can register; Google says an administrator can disable the 2-Step Verification option. If the method you want is missing, ask IT whether policy permits it.
Choose a factor you can use and recover
Prefer a supported phishing-resistant option, such as a passkey or FIDO2 security key, when your provider and organization allow it. Microsoft identifies FIDO2 security keys, passkeys, Windows Hello for Business, and certificate-based authentication as phishing-resistant methods. An authenticator app or provider prompt may be more convenient, but availability depends on the account and its policy. Do not assume every provider supports every method.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Method | What to consider | Recovery and portability |
|---|---|---|
| Passkey | Phishing-resistant when supported; a synced passkey depends on a compatible credential manager and its account or device access. | Plan how you will access the credential manager if a device is lost. Organization policy and provider compatibility apply. |
| FIDO2 security key | Phishing-resistant and requires possession of the physical key, plus compatible hardware and browser. | Keep a separately stored backup key if the service permits multiple devices. Confirm compatibility with your provider, operating system, browser, and organization before buying one. |
| Authenticator app | A practical choice where permitted; it requires access to the app on a device. | Plan for device loss. AWS recommends using the app’s cloud backup or sync feature where available. |
| Provider prompt | Can be convenient, for example Google Prompts or organization-approved Microsoft Authenticator flows. | Requires access to an approved device and is subject to identity policy. |
| SMS or voice call | May be available, but use a stronger supported method for privileged accounts when practical. | Availability and recovery depend on the provider and organization’s allowed methods. |
A no-cost authenticator app can be a suitable alternative; a hardware key is not required. For an administrator or other privileged identity, choose the strongest method the provider and organization support, and do not treat a convenient fallback as equivalent to a phishing-resistant factor.
Set up MFA: the common sequence
- Open the right identity settings. Sign in to the account that authenticates the cloud console, then use its official security or identity settings page, or follow the provider’s setup prompt.
- Choose an allowed factor. Select a passkey, security key, app, prompt, or other method offered for that account. If your preferred choice is absent on a work account, ask the administrator about policy rather than trying to bypass it.
- Complete verification. Follow the on-screen instructions and respond to the verification prompt. Enrollment is not complete until the provider confirms the factor is registered.
- Add a backup where available. Register a second device or recovery option if the service permits it. Check that your account recovery email and phone number are current and accessible.
- Test safely. Use a separate session or sign out and sign in again to confirm the factor works. In a managed environment, follow the organization’s test procedure so you do not risk losing ordinary access.
AWS: enroll a factor for the correct AWS identity
AWS supports MFA for root users, IAM users, IAM Identity Center users, and other identity types; IAM Identity Center has MFA enabled by default. AWS says every AWS account type must configure root MFA. If it is not already enabled, a root user must register MFA within 35 days of the first sign-in attempt to access the Management Console. Before enabling root MFA, confirm that you can access the account’s email and phone, which AWS identifies as important for recovery if the device fails. See AWS root-user MFA guidance.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Register a passkey or security key for an IAM user
- Sign in to the IAM console as the IAM user.
- Open Security credentials.
- Choose Assign MFA device, then select Passkey or Security Key.
- Follow the browser’s setup flow and finish its verification steps.
AWS describes FIDO keys as physical devices and says one key can support multiple root or IAM users. It permits up to eight supported MFA devices per root user or IAM user. AWS recommends registering multiple devices where possible, such as a built-in authenticator and a separately stored key. Its guidance also supports virtual authenticator apps and hardware TOTP tokens for root users. Review AWS instructions for assigning an MFA device and AWS security-credentials guidance.
Google Cloud: turn on 2-Step Verification
Google calls MFA “2-Step Verification” (2SV). For a personal Google Account, open Google Account settings, go to the Security tab, and enable 2-Step Verification by following the prompts. For an organization account, use the Google identity that actually authenticates Google Cloud; an administrator may have disabled the option. Google documents authenticator apps, Google Prompts, physical security keys, and SMS codes as additional factors for personal Google Accounts and enterprise accounts using Google as their identity provider.
Recommended Free Tools
Rank #3
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Google’s documented Google Cloud rollout applies to specified account types and console interfaces, not every identity or workload universally. The current requirement page, accessed in 2026, lists personal Google Accounts used as Google Cloud principals for requirements on or after May 12, 2025. For enterprise Cloud Identity accounts not using SSO, it lists a start on or after October 20, 2026 for organizations created before August 3, 2026, and a requirement 30 days after creation for organizations created on or after that date. Federated enterprise timing is listed as “To be announced.” The requirement covers the Google Cloud and Firebase consoles; Google Workspace has a separate 2SV requirement, and workloads or data-plane applications are not themselves subject to this console requirement. Check Google Cloud’s current 2SV requirement and schedule because rollout dates can change. Google also says accounts with passkeys must still enable 2SV and add an authentication factor under this requirement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Microsoft Entra and Microsoft 365: registration depends on policy
For a Microsoft 365 work or school account, an administrator must enable MFA before users can register. When MFA is required, sign in and follow the registration prompts, choosing an organization-approved method. Depending on policy, options can include Microsoft Authenticator, Authenticator Lite in Outlook, passkeys, Windows Hello for Business, SMS, voice calls, and hardware or software tokens. Your organization determines when verification is requested, such as at every sign-in, for particular applications, on a new device, or from outside the network. Follow Microsoft’s MFA registration instructions.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What administrators need to know
Microsoft Entra offers security defaults, per-user MFA state, and Conditional Access, which work differently. Security defaults challenge administrators and require Microsoft Authenticator challenges for users. Per-user MFA requires verification at every sign-in and overrides Conditional Access policies. Conditional Access is more flexible but is a premium Entra feature; risk-based policies require Entra ID P2 licensing. Microsoft recommends phishing-resistant MFA as the identity-security baseline. See Microsoft Entra identity-security best practices.
Protect privileged access with at least two cloud-only emergency access accounts, using methods different from normal administrator methods. Store their credentials securely, and exclude them from blocking Conditional Access policies when needed to preserve emergency usability. Microsoft advises monitoring and validating these accounts at least every 90 days. See Microsoft’s emergency access account guidance.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Recover access if a factor is lost
- Lost phone or unavailable authenticator: use a registered backup factor or the provider’s official recovery process. For a work or school account with no accessible registered method, contact your IT administrator.
- Lost AWS FIDO key: AWS says to deactivate the old authenticator before adding a replacement. If a new key is unavailable, a virtual MFA device or hardware TOTP token can be enrolled where supported.
- AWS root account recovery: use the account recovery process and ensure the account email and phone are accessible; AWS specifically advises validating those contacts before enabling root MFA.
- Factor option missing: check whether you are signed into the correct identity, whether the device or browser supports the method, and whether organization policy permits it. Ask the administrator for a work account.
Do not remove a working factor until its replacement has been enrolled and tested, unless the provider’s recovery instructions explicitly require deactivation first.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




