Skip to main content

    Set Up MFA and Know When to Reject a Prompt

    Turn on MFA in an account’s official security settings, keep recovery access safe and never approve a sign-in you did not start.

    By ZoraSafe · Content reviewed · Originally published

    Choose the strongest supported option

    CISA recommends phishing-resistant MFA. Where available, supported passkeys or security keys can provide that protection. If those are not available, use the stronger options your provider supports rather than leaving MFA off.

    Sources: CISA: Implementing phishing-resistant MFA

    Set it up through the provider

    1. Open the official app or website yourself and find account security settings.
    2. Choose and enroll an offered MFA method using that provider’s instructions.
    3. Store recovery codes privately in a secure place separate from an unexpected message or caller.
    4. Confirm you can use the method and maintain a safe recovery path before removing an old one.

    Sources: CISA: Implementing phishing-resistant MFA; FTC: How to recover your hacked email or social media account

    Know what a legitimate prompt means

    Only approve a prompt for a sign-in you initiated and recognize. Number matching can reduce the risk of accidental approval compared with a simple push notification, but it does not make every request legitimate.

    Sources: CISA: Require multifactor authentication

    If the prompts will not stop

    Deny unexpected requests, review sign-in activity through the official service and contact verified support. If you approved one or shared a code, use the account-takeover response checklist.

    Sources: FTC: How to recover your hacked email or social media account; CISA: Require multifactor authentication

    Sources and product references

    Reviewed 2026-10-07. Source dates and scope matter; a linked source supports the associated guidance, not every claim about every product.