How to Enable MFA on Google, Microsoft and AWS
Turn on multi-factor authentication (MFA) so a stolen password alone cannot open the account. On Google use 2-Step Verification (authenticator or security key), on Microsoft use security defaults or per-user MFA in Entra ID, and on AWS assign an MFA device to the root user and to every IAM user you sign in with.
Friends, even if the password is stolen the account can stay safer — that is MFA’s promise. A 6-digit code on the phone or a security key. Today we enable Google, Microsoft and AWS in vertical steps. Default English screens for US students; button names match the consoles.
मित्रांनो, पासवर्ड चोरी झाला तरी खाते सुरक्षित राहू शकते – हे MFA चे वचन. फोनवर सहा अंकी क्रमांक किंवा सुरक्षित चावी. आज Google, Microsoft आणि AWS तीनही उभ्या पायऱ्यांनी सुरू करूया. अमेरिकन विद्यार्थ्यांसाठी इंग्रजी पडदे; बटणांची नावे कन्सोलप्रमाणेच.
मित्रों, पासवर्ड चोरी हो जाए तब भी खाता सुरक्षित रह सकता है – यही MFA का वादा. फ़ोन पर छह अंकों का कोड या सुरक्षित चाबी. आज Google, Microsoft और AWS तीनों को ऊर्ध्व चरणों में चालू करेंगे. अमेरिकी विद्यार्थियों के लिए अंग्रेज़ी स्क्रीन; बटन के नाम कंसोल जैसे ही.
Quick answer
Do these three tracks (pick the accounts you use):
Google (personal)
- Open myaccount.google.com → Security.
- Turn on 2-Step Verification.
- Add Authenticator app or a security key; keep backup codes offline.
Microsoft 365 / personal Microsoft account
- Open account.microsoft.com → Security → Advanced security options (personal), or Entra admin centre for work.
- Turn on two-step verification / require MFA.
- Register Microsoft Authenticator or another method; prefer number matching.
AWS
- Root: account menu → Security credentials → Assign MFA device.
- Create an IAM user for daily work; put the user in a group with least privilege.
- Sign in as the IAM user → Security credentials → Assign MFA device.
- Delete any root access keys.
Google: myaccount.google.com → Security → 2-Step Verification
Microsoft personal: account.microsoft.com → Security
Microsoft work: Entra ID → Users → Per-user MFA / Conditional Access
AWS root: console top-right → Security credentials → Assign MFA device
AWS IAM: IAM → Users → Security credentials → Assign MFA device
What do I need before enabling MFA?
- Phone with an authenticator app (Google Authenticator, Microsoft Authenticator, Authy, or similar) or a FIDO2 security key.
- Access to the account email / recovery options already working.
- 15–20 minutes; print or store backup codes somewhere offline.
How does MFA stop account takeover?
A password alone is not enough. The second factor from your phone or security key blocks most takeovers even when the password leaks.
फक्त पासवर्ड पुरेसा नाही. फोन किंवा सुरक्षित चावीतून दुसरा पुरावा येतो – पासवर्ड गळाला तरी बहुतेक जबरदस्तीने प्रवेश थंबवतो.
केवल पासवर्ड काफी नहीं. फ़ोन या सुरक्षित चाबी से दूसरा प्रमाण आता है – पासवर्ड लीक हो जाए तब भी ज़्यादातर ज़बरदस्ती प्रवेश रुक जाता है.
- Attacker steals or guesses only the password.
- Sign-in still asks for a second factor you hold (code, push with number match, or security key).
- Without that factor, the session should not open.
- You get a chance to see unusual prompts and deny them.
Prefer phishing-resistant options (security keys / passkeys) when the product offers them. SMS works as a starting point but is weaker than an app or key.
How do I enable MFA on Google?
Step 1 — Open Google security settings
- Sign in at myaccount.google.com.
- Open Security.
- Find 2-Step Verification and start enrollment.
Step 2 — Add a strong second factor
- Choose Authenticator app and scan the QR code, or add a security key.
- Confirm with a live code.
- Save backup codes offline (not in the same inbox).
- Optionally add a passkey for passwordless sign-in on trusted devices.
Ravindra Bagale's Tip
💡 Do not keep backup codes as a draft in the same inbox — if the inbox is hacked, the codes are gone too. Use paper or a secure note in your password manager. Migrate the authenticator before you change phones. Stay alert!
Ravindra Bagale's Tip – मराठी
💡 Backup codes inbox मध्ये draft ठेवू नका – inbox hack झाला की codes पण गेले. Paper किंवा password manager चा secure note. Phone बदलण्याआधी नवीन phone वर authenticator migrate करा. ध्यान राखो!
Ravindra Bagale's Tip – हिंदी
💡 Backup codes को उसी inbox में draft करके मत रखो – inbox hack हुआ तो codes भी चले गए. Paper या password manager का secure note. Phone बदलने से पहले नए phone पर authenticator migrate करो. ध्यान रखना!
How do I enable MFA on Microsoft?
Step 1 — Personal Microsoft account
- Sign in at account.microsoft.com.
- Open Security → Advanced security options.
- Turn on Two-step verification.
- Register Microsoft Authenticator or another method and test sign-in.
Step 2 — Work or school (Microsoft Entra ID)
- An admin enables Security defaults or a Conditional Access policy that requires MFA.
- Each user completes registration at aka.ms/mfasetup (or the prompt at next sign-in).
- Prefer Microsoft Authenticator with number matching over simple approve/deny pushes.
- Admins should use stronger methods (phishing-resistant) for privileged roles.
How do I enable MFA on AWS?
Step 1 — Protect the root user first
- Sign in as root.
- Open the account menu (top right) → Security credentials.
- Under Multi-factor authentication (MFA) choose Assign MFA device.
- Pick authenticator app or hardware/passkey options supported in your region.
- Enter two consecutive codes when asked.
- Delete any root access keys on the same page.
Step 2 — Daily work as an IAM user with MFA
- Create a group with only the permissions you need.
- Create an IAM user with console access; add the user to that group.
- Sign in at
https://ACCOUNT_ID.signin.aws.amazon.com/console(not the root email page). - Assign MFA to that IAM user the same way.
- Details and screenshots path: Create an IAM user with MFA.
Step 3 — Quick verify
- Sign out and sign in again — MFA prompt must appear.
- Confirm you still have backup / second device registered for recovery.
- For AWS CLI long-term keys, prefer IAM roles on EC2 / SSO over permanent keys when you can.
How do I fix common MFA setup problems?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Authenticator codes rejected | Clock drift or same code typed twice | Set phone time to automatic; enter two new consecutive codes on AWS |
| Locked out after phone loss | No backup codes / second factor | Use backup codes; for AWS root use the MFA troubleshooting flow; for work accounts call IT admin |
| MFA push fatigue | Approve-spam attack | Deny unknown pushes; switch to number matching or security keys; change password |
| AWS IAM user cannot find MFA | Signed in as root or wrong account | Use the account sign-in URL as the IAM user |
| Microsoft work account has no MFA prompt | Admin has not required MFA | Ask IT to enable security defaults or Conditional Access |
Try it at home
Enable MFA on one personal account today and write four lines:
- Which account:
- Which method (app / key / SMS):
- Where backup codes are stored:
- Date you tested a fresh sign-in:
Learn it properly
Got it? Password + second factor. Google 2-Step, Microsoft two-step / Entra MFA, AWS root and IAM both. Backup codes offline. Slow down on blind push approve — number matching or a security key is better. Your important accounts are much safer now.
समजलं का? पासवर्ड आणि दुसरा पुरावा. Google 2-Step, Microsoft two-step / Entra MFA, AWS root आणि IAM दोन्ही. बॅकअप कोड ऑफलाइन. आंधळे पुश मंजूर करू नका – क्रमांक जुळवणे किंवा सुरक्षित चावी चांगली. आता महत्त्वाची खाती खूप सुरक्षित.
समझ में आया? पासवर्ड और दूसरा प्रमाण. Google 2-Step, Microsoft two-step / Entra MFA, AWS root और IAM दोनों. बैकअप कोड ऑफ़लाइन. अंधा पुश स्वीकार मत करो – अंक मिलान या सुरक्षित चाबी बेहतर. अब ज़रूरी खाते बहुत सुरक्षित हैं.
Frequently asked questions
What does MFA mean?
Multi-factor authentication: something you know (password) plus something you have (app code, push with number match, or security key).
Is SMS MFA good enough?
It is better than nothing, but authenticator apps and security keys are stronger and more phishing-resistant.
Why does AWS reject my authenticator codes?
Often clock drift or the same code typed twice. Set automatic time and enter two consecutive new codes.
Should the AWS root user have MFA?
Yes. Protect root first, then use an IAM user with MFA for everyday work.
What if I lose my phone?
Use backup codes or a second registered factor. For work accounts, contact an admin; for AWS root, follow MFA troubleshooting.
Where is the longer AWS IAM walkthrough?
See the guide Create an IAM user with MFA on AWS on this site.