Set Up MFA and Know When to Reject a Prompt
Turn on MFA in an account’s official security settings, keep recovery access safe and never approve a sign-in you did not start.
By ZoraSafe · Content reviewed · Originally published
Choose the strongest supported option
CISA recommends phishing-resistant MFA. Where available, supported passkeys or security keys can provide that protection. If those are not available, use the stronger options your provider supports rather than leaving MFA off.
Set it up through the provider
- Open the official app or website yourself and find account security settings.
- Choose and enroll an offered MFA method using that provider’s instructions.
- Store recovery codes privately in a secure place separate from an unexpected message or caller.
- Confirm you can use the method and maintain a safe recovery path before removing an old one.
Sources: CISA: Implementing phishing-resistant MFA; FTC: How to recover your hacked email or social media account
Know what a legitimate prompt means
Only approve a prompt for a sign-in you initiated and recognize. Number matching can reduce the risk of accidental approval compared with a simple push notification, but it does not make every request legitimate.
If the prompts will not stop
Deny unexpected requests, review sign-in activity through the official service and contact verified support. If you approved one or shared a code, use the account-takeover response checklist.
Sources: FTC: How to recover your hacked email or social media account; CISA: Require multifactor authentication
Sources and product references
Reviewed 2026-10-07. Source dates and scope matter; a linked source supports the associated guidance, not every claim about every product.
