A large share of intrusions don't start with a clever vulnerability; they start with a correct password. One that leaked from another site, was typed into a fake page, or is written on a note beside the monitor. Two-step sign-in means knowing the password is no longer enough to get in.
But not every second step protects equally, and each has conditions that internal networks routinely miss.
The three common methods
SMS codes
The most familiar, and nothing to install. Its weaknesses are well known too: a SIM can be reissued to someone impersonating the owner, messages arrive late, and delivery depends on an SMS gateway and the carrier's network. Better than nothing for ordinary users; not enough for administrator accounts.
Authenticator app codes (TOTP)
Apps such as Google Authenticator or Microsoft Authenticator produce a six-digit code every 30 seconds. The code is derived from a shared secret and the time, so it needs neither the internet nor SMS. For most internal systems it's a good choice.
Two things to remember. The clock on the server that checks the code must be right; drift by more than about half a minute and every code is rejected. And TOTP codes can be phished: a user who types their password into a fake page types the code in too.
Hardware security keys (FIDO2)
A small USB or NFC device, plugged in at sign-in and confirmed with a touch. The key difference is that it checks the site's address and simply doesn't answer a fake one. Among the common methods it is the only one that resists phishing, and it works offline as well.
Side by side
| SMS | Authenticator app | FIDO2 key | |
|---|---|---|---|
| Resists phishing | No | No | Yes |
| Works without the internet | Depends on the carrier | Yes | Yes |
| Cost | An SMS per sign-in | Free | The keys, two per person |
| Main risk | SIM reissue fraud | A wrong server clock | Losing the key with no spare |
What hardware keys need
FIDO2 keys work in the browser through a standard called WebAuthn, which has two conditions internal networks often break:
- The system must be opened by name, not by IP address. Browsers won't run WebAuthn on an IP address.
- Its HTTPS certificate must be valid and trusted by the user's computer. Chrome turns WebAuthn off on a site with a certificate error.
The usual answer is an internal name such as panel.corp.example and an internal certificate authority whose root is installed on the organisation's computers.
There is a supply question too: Yubico, the best-known maker, does not ship to Iran. FIDO2-certified keys from other makers are available locally; check the key's FIDO certification before buying.
The order to roll it out
Don't make it mandatory for everyone at once. This order gives the most protection for the least resistance:
- Administrator accounts — domain admins, the firewall console, the virtualisation panel, anything with full access to infrastructure. With hardware keys if you can.
- Remote access — the VPN and anything reachable from outside the organisation.
- Email — most systems reset passwords by email; an open mailbox opens everything else.
- Everyone else — with an authenticator app and a short guide to setting it up.
Design recovery on day one
Two-step sign-in without a way back turns the first lost phone into an emergency call. Issue single-use recovery codes at enrolment and ask for them to be kept away from the phone. For hardware keys, register two per person: one on the keyring, one in the safe. And never let an administrator account be recovered by a phone call alone; that is exactly the route an attacker will try.
In summary
If you have no second step today, turn on an authenticator app this week for administrator accounts and remote access. Hardware keys come next, for the people whose leaked password would open the whole organisation.