August 2026 | Nextworks
Two-factor authentication (2FA) requires two distinct forms of identification to verify identity before granting access to an account or system.
Common 2FA Methods
SMS and email methods are being phased out in favor of authenticator apps.
Attackers have repeatedly compromised SMS and email channels.
Apps such as Google Authenticator, Microsoft Authenticator, or Authy generate short-lived TOTP codes locally on the user’s device.
Setup and verification work as follows:
Because the codes are short-lived and derived from a secret stored only on the device (and the server), they eliminate dependence on carrier or email delivery channels.
CISA and the FBI explicitly advise against SMS-based 2FA for sensitive accounts, citing interception risks and documented telecom-network compromises.
Microsoft will retire SMS (and voice delivery) 2FA for Microsoft 365 (Entra ID) on February 1, 2027. Organizations that still require telephony methods may continue them. However, doing so means swimming up river and requires a number of overides.
Wherever a service offers an authenticator-app option, enable it — especially for email, password managers, banking, and other high-value accounts. Most account settings pages allow this change directly.
SMS remains preferable to no second factor and continues to be used where authenticator apps are unsupported.
Authenticator apps themselves are not invulnerable; they remain susceptible to phishing, device malware, and other attacks. They should therefore be treated as one additional layer within a broader defense-in-depth strategy rather than a complete solution.
Goodbye to IT headaches and hello to IT proficiency. Locally owned and operated, Nextworks has earned a 5-star rating on Google. We guarantee IT cohesion in 30 days or less, or your money back.