Ravindra BagaleCourses & study guides Track your progress

Guides

How to Enable MFA on Google, Microsoft and AWS

Turn on multi-factor authentication (MFA) so a stolen password alone cannot open the account. On Google use 2-Step Verification (authenticator or security key), on Microsoft use security defaults or per-user MFA in Entra ID, and on AWS assign an MFA device to the root user and to every IAM user you sign in with.

Friends, even if the password is stolen the account can stay safer — that is MFA’s promise. A 6-digit code on the phone or a security key. Today we enable Google, Microsoft and AWS in vertical steps. Default English screens for US students; button names match the consoles.

Quick answer

Do these three tracks (pick the accounts you use):

Google (personal)

  1. Open myaccount.google.com → Security.
  2. Turn on 2-Step Verification.
  3. Add Authenticator app or a security key; keep backup codes offline.

Microsoft 365 / personal Microsoft account

  1. Open account.microsoft.com → Security → Advanced security options (personal), or Entra admin centre for work.
  2. Turn on two-step verification / require MFA.
  3. Register Microsoft Authenticator or another method; prefer number matching.

AWS

  1. Root: account menu → Security credentials → Assign MFA device.
  2. Create an IAM user for daily work; put the user in a group with least privilege.
  3. Sign in as the IAM user → Security credentials → Assign MFA device.
  4. Delete any root access keys.
Google:   myaccount.google.com → Security → 2-Step Verification
Microsoft personal: account.microsoft.com → Security
Microsoft work: Entra ID → Users → Per-user MFA / Conditional Access
AWS root: console top-right → Security credentials → Assign MFA device
AWS IAM:  IAM → Users → Security credentials → Assign MFA device

What do I need before enabling MFA?

  • Phone with an authenticator app (Google Authenticator, Microsoft Authenticator, Authy, or similar) or a FIDO2 security key.
  • Access to the account email / recovery options already working.
  • 15–20 minutes; print or store backup codes somewhere offline.

How does MFA stop account takeover?

MFA on Google, Microsoft and AWS Password alone is not enough. A second factor from your phone or security key blocks most account takeovers. Passwordsomething you know + MFA codesomething you have Signed insafer 2FA

A password alone is not enough. The second factor from your phone or security key blocks most takeovers even when the password leaks.

  1. Attacker steals or guesses only the password.
  2. Sign-in still asks for a second factor you hold (code, push with number match, or security key).
  3. Without that factor, the session should not open.
  4. You get a chance to see unusual prompts and deny them.

Prefer phishing-resistant options (security keys / passkeys) when the product offers them. SMS works as a starting point but is weaker than an app or key.

How do I enable MFA on Google?

Step 1 — Open Google security settings

  1. Sign in at myaccount.google.com.
  2. Open Security.
  3. Find 2-Step Verification and start enrollment.

Step 2 — Add a strong second factor

  1. Choose Authenticator app and scan the QR code, or add a security key.
  2. Confirm with a live code.
  3. Save backup codes offline (not in the same inbox).
  4. Optionally add a passkey for passwordless sign-in on trusted devices.

Ravindra Bagale's Tip

💡 Do not keep backup codes as a draft in the same inbox — if the inbox is hacked, the codes are gone too. Use paper or a secure note in your password manager. Migrate the authenticator before you change phones. Stay alert!

How do I enable MFA on Microsoft?

Step 1 — Personal Microsoft account

  1. Sign in at account.microsoft.com.
  2. Open Security → Advanced security options.
  3. Turn on Two-step verification.
  4. Register Microsoft Authenticator or another method and test sign-in.

Step 2 — Work or school (Microsoft Entra ID)

  1. An admin enables Security defaults or a Conditional Access policy that requires MFA.
  2. Each user completes registration at aka.ms/mfasetup (or the prompt at next sign-in).
  3. Prefer Microsoft Authenticator with number matching over simple approve/deny pushes.
  4. Admins should use stronger methods (phishing-resistant) for privileged roles.

How do I enable MFA on AWS?

Step 1 — Protect the root user first

  1. Sign in as root.
  2. Open the account menu (top right) → Security credentials.
  3. Under Multi-factor authentication (MFA) choose Assign MFA device.
  4. Pick authenticator app or hardware/passkey options supported in your region.
  5. Enter two consecutive codes when asked.
  6. Delete any root access keys on the same page.

Step 2 — Daily work as an IAM user with MFA

  1. Create a group with only the permissions you need.
  2. Create an IAM user with console access; add the user to that group.
  3. Sign in at https://ACCOUNT_ID.signin.aws.amazon.com/console (not the root email page).
  4. Assign MFA to that IAM user the same way.
  5. Details and screenshots path: Create an IAM user with MFA.

Step 3 — Quick verify

  1. Sign out and sign in again — MFA prompt must appear.
  2. Confirm you still have backup / second device registered for recovery.
  3. For AWS CLI long-term keys, prefer IAM roles on EC2 / SSO over permanent keys when you can.

How do I fix common MFA setup problems?

Ghabru naka 😅 — these are the usual ones:

Symptom Likely cause Fix
Authenticator codes rejected Clock drift or same code typed twice Set phone time to automatic; enter two new consecutive codes on AWS
Locked out after phone loss No backup codes / second factor Use backup codes; for AWS root use the MFA troubleshooting flow; for work accounts call IT admin
MFA push fatigue Approve-spam attack Deny unknown pushes; switch to number matching or security keys; change password
AWS IAM user cannot find MFA Signed in as root or wrong account Use the account sign-in URL as the IAM user
Microsoft work account has no MFA prompt Admin has not required MFA Ask IT to enable security defaults or Conditional Access

Try it at home

Enable MFA on one personal account today and write four lines:

  1. Which account:
  2. Which method (app / key / SMS):
  3. Where backup codes are stored:
  4. Date you tested a fresh sign-in:

Got it? Password + second factor. Google 2-Step, Microsoft two-step / Entra MFA, AWS root and IAM both. Backup codes offline. Slow down on blind push approve — number matching or a security key is better. Your important accounts are much safer now.

Frequently asked questions

What does MFA mean?

Multi-factor authentication: something you know (password) plus something you have (app code, push with number match, or security key).

Is SMS MFA good enough?

It is better than nothing, but authenticator apps and security keys are stronger and more phishing-resistant.

Why does AWS reject my authenticator codes?

Often clock drift or the same code typed twice. Set automatic time and enter two consecutive new codes.

Should the AWS root user have MFA?

Yes. Protect root first, then use an IAM user with MFA for everyday work.

What if I lose my phone?

Use backup codes or a second registered factor. For work accounts, contact an admin; for AWS root, follow MFA troubleshooting.

Where is the longer AWS IAM walkthrough?

See the guide Create an IAM user with MFA on AWS on this site.