Short answer: Sign in at zoom.us, open Profile → Sign In → Two-factor authentication and click Turn on. Choose Authentication App, scan the QR code, enter the six-digit code, and save the recovery codes. If you sign into Zoom with Google or SSO, your 2FA lives on that account instead — secure it there.
Why a Zoom account is worth protecting
It is not the meetings themselves so much as everything attached to them. A compromised Zoom account can hold cloud recordings of internal calls, meeting transcripts, chat history, contact lists, and — for paid accounts — billing details.
For anyone running a business, the more immediate risk is impersonation. Someone with access to your account can schedule meetings that appear to come from you, join calls as you, and reach your contacts with a level of trust no cold email achieves.
There is also a specific problem with recordings. Sessions people assumed were private end up as files sitting in the cloud, often for years, and often forgotten by the person who recorded them.
First: check how you actually sign in
This trips up a lot of people. Zoom’s own two-factor setting only applies if you sign in with a Zoom email and password.
If you sign in with Google, Facebook, Apple or your company’s SSO, Zoom hands authentication to that provider. Enabling 2FA inside Zoom will not appear as an option, and the security that matters is on the upstream account.
In that case, secure the account you actually log in with — Google, Apple, Facebook — and you are done.
Step 1: Turn on two-factor authentication
- Sign in at zoom.us in a browser.
- Click Profile in the left menu.
- Scroll to the Sign In section.
- Find Two-factor authentication and click Turn on.
- Enter your Zoom password to confirm.
Step 2: Choose the authentication app
Zoom offers two methods:
- Authentication App — six-digit codes generated offline on your device. Choose this.
- SMS — a text code, exposed to SIM swap attacks. See SMS vs authenticator apps for the comparison.
Select Set up next to Authentication App. Zoom displays a QR code with a manual key beneath it. Scan it with Google Authenticator, Aegis, 2FAS, Microsoft Authenticator, Authy, or your password manager. If you are new to this, start with what is an authenticator app.
Enter the six digits to confirm, and do not screenshot the QR code — it contains the raw secret key. This warning carries extra weight for Zoom users: setting this up while screen sharing is exactly the kind of accident that happens on a busy day.
Step 3: Save the recovery codes
Zoom generates recovery codes immediately after setup. Download them and store them offline or in an encrypted vault — see where to store 2FA backup codes safely.
Zoom support can help with account recovery, but on a work account that means a ticket, verification, and a delay measured in hours or days. If a meeting is starting in ten minutes, the recovery codes are the difference between a hiccup and an absence.
For account admins: enforce it
If you administer a Zoom account for a team, you can require two-factor authentication for everyone rather than hoping people opt in.
- Sign in as an admin and go to Advanced → Security in the admin portal.
- Enable Sign in with Two-Factor Authentication.
- Choose the scope: all users, users in specific roles, or users in specific groups.
Applying it to admins and anyone who can access cloud recordings is the minimum. Give people a week’s notice and a one-page instruction sheet — resistance is nearly always confusion rather than objection. Our guide to 2FA for small teams covers the rollout pattern.
The meeting security settings people forget
Two-factor authentication protects your account. It does nothing about the meetings themselves, and that is where most Zoom incidents actually happen:
- Require a passcode for all meetings, and use the waiting room for anything sensitive.
- Do not post meeting links publicly, including in social posts and screenshots.
- Lock the meeting once everyone has arrived.
- Restrict screen sharing to the host by default.
- Review cloud recordings and delete what you do not need. Check who has access to the ones you keep.
- Check your Personal Meeting ID usage — reusing it for everything means anyone who has ever joined can rejoin any future meeting.
Frequently asked questions
I can’t find the 2FA option in Zoom. Why?
Almost certainly because you sign in with Google, Apple, Facebook or SSO. Zoom only shows its own two-factor setting for email-and-password accounts. Secure the provider account instead.
Does 2FA work on the Zoom desktop and mobile apps?
Yes. Once enabled on your account it applies to every client. You will be asked for a code when signing in on a new device.
Which authenticator app works with Zoom?
Any standard TOTP app — Zoom uses the normal algorithm. See how TOTP codes work.
Why is Zoom rejecting my code?
Usually your phone’s clock has drifted out of sync. Turn on automatic network time. More causes: why 2FA codes get rejected.
What if I lose my phone before a meeting?
Use a recovery code. If you have neither, an account admin can disable 2FA for your user, or Zoom support can help — both take time you may not have. This is why the codes matter. See recovering accounts after losing your 2FA phone.
Does Zoom support security keys or passkeys?
Consumer accounts are limited to authenticator apps and SMS. Enterprise deployments using SSO can enforce phishing-resistant methods at the identity provider — see phishing-resistant MFA.
The bottom line
Check how you sign in first — that one question decides whether you configure 2FA in Zoom or somewhere else entirely. If it is a Zoom password account, three minutes gets you the app, the recovery codes, and a meaningfully harder account to steal. Then spend five more on meeting passcodes and old cloud recordings, because that is where the embarrassing incidents come from.
Need a code to test the setup? Our free online 2FA code generator runs entirely in your browser.