Short answer: Start with their email account and nothing else. Use whichever method they will actually manage — often SMS or their phone’s built-in prompts rather than a separate app. Write the recovery codes on paper and keep a copy yourself. Then teach one rule, in one sentence: nobody ever needs the code from your phone. That sentence prevents more losses than any setting.

Get the goal right first

The instinct is to do a thorough job — authenticator app, backup codes, passkeys, the lot. Resist it.

Security that gets switched off next week because it was confusing is worth nothing. Security that stays on for ten years, even if it is only SMS, is worth a great deal. The aim is durable, not optimal.

Older users are also targeted disproportionately by scam calls, and those calls do not care what 2FA method is in use. Which is why the conversation matters at least as much as the configuration.

Do one account: their email

If you do nothing else, do this.

Their email is the reset path for their bank, their shopping accounts, their photos and everything else. Securing it protects all of those indirectly. Setting up 2FA on six services in one afternoon guarantees confusion; setting it up on one, well, does not.

Guides: Google, Microsoft, Apple Account.

Come back in a month, see how it has gone, and only then consider adding their bank or their Facebook.

Choosing a method they will keep

Be honest about the person in front of you rather than about best practice.

Their phone’s built-in prompt — Google prompts on Android, Apple’s verification codes on iPhone. Usually the best option: nothing extra to install, and it appears on the device they already hold.

SMS — technically the weakest, and still a large improvement over nothing. It stops the automated attacks that account for most compromises (credential stuffing). If it is the only method they will tolerate, use it. The theoretical SIM swap risk is a poor reason to leave them with no protection at all.

An authenticator app — right for someone comfortable with apps, wrong for someone who finds their phone confusing. If you use one, put it on the home screen with a clear name and show them exactly where the number appears. Start with what is an authenticator app.

Passkeys — worth considering for iPhone users, because signing in becomes a face check with no code at all. Genuinely simpler once set up, though the setup itself needs explaining. See passkeys vs 2FA.

Set up the safety net properly

This is the part where you save yourself a stressful phone call in two years.

If they lose the phone later, the recovery process is much easier when someone has this information — see recovering accounts after losing a 2FA phone.

The one rule that matters most

Say it plainly, and say it more than once:

“If anyone asks for the code on your phone, they are stealing from you. It does not matter who they say they are. Hang up.”

Not “be careful with codes”. Not a list of exceptions. One sentence, no nuance, because nuance is what scammers exploit.

Supporting points worth adding, briefly:

More on the specific scripts in circulation: OTP scams.

How to explain it without the jargon

Analogies that land:

That last one is often the unlock. Most people have already used 2FA for years without knowing the term.

What not to do: explain the mechanism, mention hashing, list attack types, or make them feel foolish for asking twice. Show the steps slowly, let them do the tapping themselves, and write down where the setting lives.

Frequently asked questions

They refuse — what now?

Do not force it. Do the achievable things instead: a unique strong password on their email, login alerts turned on, and the one-sentence rule about codes. Revisit later, perhaps after a news story about scams gives you a natural opening.

Should I have access to their accounts?

Talk about it openly rather than arranging it quietly. Many families find a middle ground: they keep control, you hold a sealed copy of recovery codes for emergencies. Formal options exist too — Apple’s recovery contacts, Google’s inactive account manager.

Is SMS really acceptable?

For someone who would otherwise have nothing, yes. Add a port-out PIN with their carrier if you can, and revisit the method later once they are comfortable.

What about a shared family password manager?

Excellent if they will use it, and it solves the “I’ve forgotten my password” call permanently. Family plans allow shared emergency access. See do password managers get hacked? for the reassurance question that usually comes next.

They keep getting locked out. What am I doing wrong?

Usually the method is too complex for daily use, or the phone’s clock is manual. Simplify the method and check the time setting — those two fix most cases.

How do I check on it later?

Ask once every few months whether they have had any odd calls or codes. It doubles as a check on whether the setup is still working and whether anyone has been targeting them.

The bottom line

One account, one method they will keep, codes on paper with a copy at your house, and one sentence they will remember. That combination protects far more than a perfect setup they turn off in frustration — and the sentence about never sharing a code is the part that will actually save them money.

Setting up your own security too? Start with our complete guide to 2FA.

Leave a Reply

Your email address will not be published. Required fields are marked *