Setting Up Passkeys and Authenticator Apps: A Step-by-Step Guide for Your Main Accounts

TL;DR: Knowing you should move beyond SMS-only authentication is one thing — actually setting it up is another. This is a practical, account-by-account walkthrough for setting up authenticator apps and passkeys on the accounts that matter most: email, banking-adjacent logins, and major platforms.

Once you understand why SMS-only 2FA has gaps, the next question is simply: how do I actually turn on something stronger? Here's the practical setup process, starting with the accounts worth prioritising.

Where to Start: Prioritise by Impact

Not every account needs the same level of protection immediately. Start with:

  • Your primary email — because it's usually the recovery point for everything else
  • Banking and UPI apps that support app-based or biometric authentication
  • Any account tied to your professional identity — LinkedIn, work email, cloud storage

Setting Up an Authenticator App

Google Authenticator, Microsoft Authenticator, and Authy are the most widely used options, and the setup process is broadly similar across platforms:

  • Step 1: Install an authenticator app from your phone's app store
  • Step 2: Go to the security settings of the account you want to protect — typically under "Security," "Login & Security," or "Two-Factor Authentication"
  • Step 3: Choose "Authenticator App" or "TOTP" as your 2FA method instead of, or in addition to, SMS
  • Step 4: Scan the QR code shown on screen using your authenticator app
  • Step 5: Enter the 6-digit code the app generates to confirm the setup is working
  • Step 6: Save the backup codes provided at this stage — store them somewhere secure and separate from your phone, since they're your recovery option if you lose access to the authenticator app

Setting Up a Passkey

Passkeys are newer and increasingly supported by major platforms — Google, major banks, and several Indian apps have begun rolling them out. The process typically looks like:

  • Step 1: Go to the account's security settings and look for "Passkey" or "Sign in with passkey"
  • Step 2: Select "Create a passkey"
  • Step 3: Your device will prompt for biometric verification — fingerprint or face unlock — or your device PIN
  • Step 4: The passkey is now stored securely on your device (and often synced to your cloud account, like Google or Apple's password manager, for use across devices)

Passkeys are generally considered stronger than both SMS and app-based OTPs because there's no code to intercept, phish, or trick someone into entering — authentication happens through your device directly.

What to Check After Setup

  • Confirm SMS is no longer the only method available, even if you keep it as a fallback
  • Store backup codes somewhere separate from your phone — a password manager's secure notes feature works well
  • Repeat this process for each priority account rather than assuming one setup covers everything, since 2FA is configured per-account, not device-wide
  • Periodically review which devices and methods are registered under your account's security settings, removing any you no longer use

This builds directly on the reasoning covered in two-factor authentication and account recovery: closing the gaps attackers actually use — that article explains why this matters; this is the practical setup itself.

Before deciding which accounts to prioritise first, it helps to know what's already exposed. Scan My Shadow checks your phone number and email across 1,500+ sources and returns a report highlighting where your identifiers already circulate.

Frequently Asked Questions

What happens if I lose my phone after setting up an authenticator app?

This is why backup codes matter — most services provide them during setup specifically for this scenario. Without backup codes, recovery can be more complicated and may require identity verification through the platform's support process.

Can I use one authenticator app for multiple accounts?

Yes. A single authenticator app can hold codes for many different accounts simultaneously — each account you add appears as a separate entry within the same app.

Are passkeys supported by Indian banks yet?

Support varies by institution and is expanding gradually as the RBI's authentication framework encourages movement beyond SMS-only methods. Checking your specific bank's app settings is the most reliable way to confirm current support.

Is it safe to sync passkeys to the cloud?

Cloud-synced passkeys (through Google or Apple's system) are generally considered secure, as they remain encrypted and tied to your account's own authentication. This also makes recovery easier if you switch devices.

Do I still need an authenticator app if I've set up a passkey?

Not necessarily for the same account, but many platforms don't support passkeys yet, so an authenticator app remains useful as your primary method for those services in the meantime.

Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.

Comments

Popular posts from this blog

UPI Fraud Prevention in India: Complete Guide to Protect Your Digital Payments in 2024

Children’s Data and the DPDP Act: What Parents Should Know

Digital Arrest Scams Rise 200% in India: New AI-Powered Cyber Threats Target Professionals in 2026