LThe Life Starter
0 of 6 complete0%
Lesson 3 of 6
Digital · Guided lesson

Turn on stronger sign-in

Add a second barrier and secure the fallback paths around it.

About 23 minutes Finish with a concrete deliverable
Cybersecurity and Infrastructure Security AgencySecure Our WorldYouTube
Course primer

Secure Our World

From Cybersecurity and Infrastructure Security Agency. Watch here or open it on YouTube .

Compare the MFA options in CISA's materials with each provider's current security settings; choose phishing-resistant methods wherever they exist.
Before you begin

What this lesson is really solving.

Prefer passkeys or hardware security keys where supported, then authenticator apps, with SMS as a weaker fallback when nothing stronger is available. Register more than one safe method, store recovery codes securely, and remove obsolete devices.

Why this works

Understand the idea before touching the steps.

Multifactor authentication is only as strong as its recovery and weakest allowed method.

Do this

Follow these steps in order.

Take the action in each step; then use the deliverable below to prove the lesson is finished.

  1. 1

    Prefer passkeys or hardware security keys where supported, then authenticator apps; use SMS when stronger options are unavailable.

  2. 2

    Register at least two recovery-capable authenticators or keys for critical accounts.

  3. 3

    Save single-use backup codes offline and remove obsolete phones, sessions, app passwords, and trusted devices.

  4. 4

    Protect the mobile-carrier account with a PIN and port-out protection when available.

Worked example

See the standard in context.

Sam adds two security keys to primary email, keeps one separate, stores recovery codes offline, and removes an old phone. A bank that offers only app approval is secured with that method and carrier-account protections are strengthened to reduce SIM-swap risk.

Quality check

Inspect before you move on.

  • The strongest available method is enabled on critical accounts.
  • A tested backup method exists and is not stored with the primary device.
  • Push prompts are denied unless you initiated the sign-in.
Make it real

Your deliverable

Strong MFA enabled and tested on every master-key account with offline backup codes.

Common mistake

Watch for this

Enabling MFA on one phone with no backup, then losing access when the phone fails.

You’re ready when

Prove it—don’t just recognize it.

You can sign in and recover without relying on a single device or insecure fallback.

Objective evidence · 3 questions

Quick knowledge check

Answer from the lesson—not from confidence alone. Score at least 2 of 3 to unlock completion.

Not yet passed

This curriculum-aligned check is scored automatically and stored with your account when signed in. It is an objective learning signal, but it has not yet been independently validated as a standardized assessment.

1Which action belongs in the recommended process for “Turn on stronger sign-in”?
2Which result is the clearest evidence that this lesson’s work is complete?
3Which choice matches the failure this lesson specifically warns against?
0 of 3 answeredEach question measures the action, evidence, or failure condition taught above.
Useful for this course

Tools, templates, and references

The Life Starter toolkitReusable planners and trackers for practical projects.
Check current detailsReferences reviewed September 9, 2026. Lesson exercises are editorial synthesis; official rules come from the linked sources.
CISA — Secure Our WorldNIST — Small business cybersecurity
3
One check remains

Pass the knowledge check above first.

Completion unlocks after a score of 2 out of 3. Then confirm that you produced the lesson deliverable.

Go to the knowledge check