Turn on two-factor authentication
Turn on two-factor authentication
Two-factor authentication (2FA) means a stolen password is not enough to get into your account. Given what my-id.ca stores, it is worth the thirty seconds.
If 2FA is off, Settings shows an amber warning saying so. That warning is the app telling you something true.
Setting it up
- Open Settings → Two-factor authentication.
- Click Enable 2FA on the Authenticator app (TOTP) row.
- Scan the code with your authenticator app.
- Enter the 6-digit code it shows, to prove the pairing worked.
From then on, signing in with your password asks for a current code from the app.
Which app
Any app that supports TOTP — the standard behind the 6-digit rotating codes:
- Google Authenticator
- Authy
- Microsoft Authenticator
- The authenticator built into 1Password, Bitwarden, or a similar password manager
Prefer one that backs up or syncs across devices. The most common way people lock themselves out is dropping the phone that held the only copy.
How it interacts with passkeys
A passkey sign-in does not ask for a code. This is deliberate, not a bug: a passkey is already two factors — the device you hold, plus the fingerprint, face, or PIN that unlocks it. See Sign in with a passkey.
Keep 2FA enabled anyway. It protects every sign-in that still uses your password — a borrowed computer, a browser where you have not set up a passkey, the recovery path after you lose a device.
The strongest practical setup is both: passkeys for daily use, 2FA guarding the password fallback.
Turning it off
The same row shows Disable 2FA once it is on. Only do this if you are replacing it with something stronger, not because the codes are annoying.
Avoiding a lockout
- Use an app that syncs or backs up.
- Register a passkey on a second device as an independent way in.
- Keep the account email address current — recovery goes through it.
- Do not enable 2FA on a phone you are about to replace. Set it up on the new one.
If you are locked out, contact support from the email address on the account.
Related
Frequently asked questions
- Which authenticator app should I use?
- Any TOTP app works — Google Authenticator, Authy, Microsoft Authenticator, 1Password, Bitwarden. Prefer one that backs up or syncs, so replacing your phone does not lock you out.
- Why did it not ask for a code when I signed in?
- You almost certainly signed in with a passkey. Passkeys skip the code because they are already two factors on their own.
- I lost my phone. How do I get in?
- Use a passkey on another device if you registered one. Otherwise contact support from the email address on the account.