Security

Enabling and Auditing Google 2-Step Verification on Android

2-Step Verification on Android has six different second-factor options. Picking the right one matters.

Adrián Vega

By Adrián Vega

Published 2 February 2026 · Updated 24 June 2026 · 7 min read

Phone showing verification code

For a long time, I thought a "strong" password was enough. I had a 16-character mix of symbols and numbers, and I felt invincible. Then I saw a report about how a database leak from a site I used once in 2018 exposed that password. If I hadn't had 2-Step Verification (2SV) turned on, my entire digital life—Gmail, Photos, Drive—would have been wide open. Android users have it easier than most because Google has baked these security layers directly into the operating system. But not all "second steps" are created equal. Some are like a deadbolt; others are more like a "Please Knock" sign.

The six second factors

The six second factors
Illustration — The six second factors. Stock photograph, not an actual device screenshot.

Google currently supports several different ways to prove it’s you. You have Google Prompts (the "Is this you?" pop-up on your phone), Authenticator apps (temporary 6-digit codes), Security keys (physical USB or NFC devices), SMS codes, Voice calls, and Backup codes.

I usually recommend having at least three of these set up. Why three? Because phones break and numbers get lost. If you only rely on a text message and you lose your phone on a hike, you’re locked out of your account while trying to set up a new phone—a classic catch-22. I personally use Google Prompts as my primary, an Authenticator app as my backup, and I keep physical backup codes in my actual, physical safe at home for emergencies.

Google prompt

This is the most seamless way to secure your account on Android. When you sign in on a new computer, your phone vibrates. You unlock it, tap "Yes, it's me," and you're in. No typing codes, no waiting for a text. Under the hood, this uses a secure encrypted connection between Google's servers and your specific hardware.

On your phone, you can find this under Settings > Google > Manage your Google Account > Security > 2-Step Verification. It’s much harder for a hacker to intercept a Google Prompt than an SMS message. The only real downside—and this happens to me occasionally—is that if your phone is in a "dead zone" with no Wi-Fi or data, the prompt won't show up. That’s why you can’t rely on it as your only method.

Authenticator app

This is my preferred backup. You can use Google Authenticator, but I actually prefer 2FAS or Microsoft Authenticator because they allow for encrypted backups. The app generates a new 6-digit code every 30 seconds. Since it’s purely math-based and happens locally on your device, it works even if you’re in airplane mode or in a basement with no service.

To set this up, you'll go to the 2SV settings on your Google account, select "Authenticator app," and scan a QR code with your phone. A quick tip: many people don't realize that you can have the same Authenticator account on two different devices. I have mine on my Pixel 8 and an old tablet. If one dies, I'm not stuck. Just be careful: if you delete the app without having a backup of the "seeds," those codes are gone forever.

Why SMS is the weakest

Why SMS is the weakest
Illustration — Why SMS is the weakest. Stock photograph, not an actual device screenshot.

I used to think SMS codes were great until a friend of mine went through a "SIM swap" attack. A hacker called his carrier, pretended to be him, and moved his phone number to a new SIM card. Within minutes, the hacker had reset his Google password using "recovery via SMS."

SMS is incredibly convenient, but it’s the most vulnerable factor. It travels over the cellular network in a way that can be intercepted or redirected. Google actually tries to move users away from this now, often defaulting to Google Prompts instead. If you have any other form of 2SV set up, I actually suggest removing your phone number as a 2SV "step" entirely. Keep it for account recovery if you must, but don't let it be the second key to your front door. It’s one of those rare cases where the "default" way is actually the least secure.

Backup codes

This is the "break glass in case of emergency" option. Google will give you a list of ten 8-digit codes. Each one works exactly once. I cannot stress this enough: print these out. Don't save them as a screenshot on your phone (if you lose your phone, you lose the codes) and don't save them in your Google Drive.

I keep a printed copy in my wallet and another in a file folder at home. They are the only way to get back into your account if you lose your phone and your physical security key at the same time. If you use one, cross it off. Once you get down to two or three codes left, go back into your 2SV settings and generate a new set. This is the ultimate safety net that prevents you from becoming one of those people posting on forums about how they lost 15 years of photos because their phone fell in a lake.

Auditing your factors

Go to your Security tab right now and see what's listed under 2-Step Verification. You might see an old phone you traded in last year still listed as a "Trusted Device" that can receive prompts. I once found my old Nexus 6P still on my list—an intruder could have technically used that old hardware to bypass my security if they’d found it in a drawer.

Tap on the devices you don't use anymore and hit "Sign out." While you're there, check which "Trust this device" cookies are active. If you’ve logged into Google on a public library computer or a friend’s laptop and checked the "Don't ask again" box, that computer is now a bypass for your 2SV. You can hit "Revoke all" to force every single device (except the one you're currently using) to ask for a code again the next time they sign in. It’s a bit of a hassle to log back in everywhere, but it’s the only way to be 100% sure the door is locked. Think of it as a digital spring cleaning—it feels great once it's done.

Key takeaways

  • The six second factors is where you start — it's the fastest win.
  • Google prompt: don't skip this — it's where most users leave settings at risky defaults.
  • Authenticator app: don't skip this — it's where most users leave settings at risky defaults.
  • Why SMS is the weakest: don't skip this — it's where most users leave settings at risky defaults.
  • Recheck these settings quarterly; OEM updates can reset toggles.

Frequently asked questions

Does changing these settings break apps?
Almost never. Modern Android apps must handle a denied permission or restricted access gracefully — they either skip the feature or prompt again when needed.
Will this drain my battery?
No. If anything, restricting background access and disabling tracking pipelines reduces battery and data usage.
Do these steps apply to Android 13, 14 and 15?
Yes. The menu paths shift slightly between versions and OEM skins (Pixel/stock, Samsung One UI, Xiaomi HyperOS), but the underlying controls behave the same.

References & further reading

Continue reading

Related guides