Organising two-factor authentication across dozens of accounts

Practical guides · About 8 minutes

Turning on 2FA for one account is a two-minute job. Turning it on for forty is a filing problem, and filing problems fail differently: not with a breach, but with you standing in an airport holding a dead phone, locked out of the account that unlocks the others. This guide is about the filing.

Know what each factor is actually protecting you from

Second factors are usually presented as a ladder from worse to better, which is true but not very actionable. It's more useful to know which attack each one stops, because that tells you where to spend effort.

FactorStopsDoesn't stop
SMS codes Someone who only has your password SIM swaps, and phishing pages that ask for the code and relay it instantly
TOTP app (6-digit rotating codes) Password-only attackers, SIM swaps, carrier-level interception Real-time phishing — the code is still something you can be tricked into typing elsewhere
Push approval The same as TOTP, with less typing "Approval fatigue" — repeated prompts until someone taps yes to make them stop
Hardware security key / passkey All of the above, including real-time phishing, because the key checks the site's identity before responding Someone with physical possession of the key and your unlocked device

The important row is the last one. Hardware keys and passkeys are the only common factor that defends against a convincing fake login page, because the browser and key together verify which site is asking. A human being cannot reliably do that check at 8am on a phone screen, and it's unfair to expect them to.

Where to spend the effort

Put hardware keys or passkeys on the handful of Tier 1 accounts that control everything else — registrar, DNS, primary email, cloud root, and your password manager. Use a TOTP app for everything else. That split gets you most of the protection for a manageable amount of work.

SMS is worth a note of nuance: it is genuinely better than nothing, and for a Tier 3 reporting tool that offers nothing else, take it. Just don't let it be the factor guarding an account that can reset your other accounts.

The seed is the secret, not the code

The QR code you scan when enabling a TOTP app isn't a one-time handshake — it encodes a shared secret, and anything holding that secret can generate valid codes forever. Two consequences follow, and most 2FA mishaps trace back to missing one of them.

First: a screenshot of that QR code is a credential. If it's sitting in your camera roll, syncing to a photo cloud, or pasted into a setup ticket, treat it exactly as you'd treat the password. Delete it, or store it with the same care.

Second: you can enrol the secret in more than one place. That is the fix for the "my phone died and now I'm locked out" problem, and it's much easier to do at setup time than to retrofit. Most services show a "can't scan the code?" link that reveals the secret as text — capture it while you're there.

Which leads to the question people actually argue about.

Should TOTP codes live in your password manager?

Storing TOTP seeds alongside passwords in the same vault means one compromised vault yields both factors — you've collapsed two factors into one. That's a real objection and it's why the purist answer is "keep them separate".

But the honest comparison isn't against a perfectly disciplined separate setup. It's against what people actually do when 2FA is inconvenient across forty accounts, which is to not turn it on, or to fall back to SMS. A vault that holds both, protected by a strong master password and a hardware key, is meaningfully better than a tidy theory nobody follows.

A reasonable middle position, and the one worth defaulting to:

Backup codes deserve an actual filing decision

Almost every service hands you a set of single-use recovery codes when you enable 2FA. Almost everyone closes that dialog and never thinks about them again. These codes bypass your second factor entirely — they are, functionally, spare keys.

Decide once where they go, and apply it every time:

Buy the second hardware key

If you go the hardware key route, register two from the start and put the second one somewhere physically separate — a drawer at home, a safe, wherever isn't your bag.

This is the single most-skipped step in every hardware key setup, and the reason is understandable: the second key costs money and solves a problem you don't have yet. But re-registering a lost key across every Tier 1 account without a backup means falling all the way through to identity-verification support processes, which are slow, unpleasant, and occasionally unsuccessful. Register the backup at the same time as the primary, while you're already logged into everything and the account list is in front of you.

The shared-account problem

2FA on an account several people use is genuinely awkward, and the awkwardness is why teams turn it off. Don't. Options, best first:

Stop sharing the account. Nearly always the right answer — see the guide on sharing access. Individual accounts make this whole problem disappear, since each person manages their own factor.

Share the TOTP seed through the vault. Where the account genuinely can't be split, put the seed in the same shared vault collection as the password so any authorised person can generate a code. The factor is no longer strictly "something only you have" — but it still defeats a stolen-password attack, which is the threat you're realistically facing.

Register multiple hardware keys. Many services allow several keys on one account. Where that's supported and the group is small, give each person their own registered key: shared account, unshared factors.

What not to do is route the factor through one person's phone. It makes that person a bottleneck, guarantees codes get relayed over chat, and ends — every time — with someone quietly disabling 2FA to get their work done.

Protect the recovery path, not just the login

Every 2FA setup has a back door, and it's usually your email account. If an attacker controls the mailbox that receives password resets, most of your second factors become negotiable — reset the password, complete the reset flow, and 2FA is often re-enrollable from there.

So: your primary email is Tier 1, whatever else you decide. Give it the strongest factor available, and then audit what's attached to it.

That last one is more common than it sounds, and it's invisible until the day it matters.

Rehearse losing your phone

Set aside thirty minutes and walk through it deliberately. Not hypothetically — actually check each step.

  1. Your phone is gone. Can you still reach your password manager? (If its second factor was on that phone, stop here and fix it — this is the failure that cascades.)
  2. Can you get into your primary email using something you still have?
  3. Can you get into your registrar and DNS?
  4. Find your backup codes. Not "know roughly where they are" — locate them.
  5. Try one on a Tier 3 account to confirm the codes are current and that you're reading them correctly.
  6. Write down what you couldn't do, and fix those specific gaps.

Most people discover exactly one broken link, and it's almost always the same one: the authenticator app was only ever on the lost phone, and the backup codes were saved into a note that syncs to it. Finding that on a quiet afternoon is a very different experience from finding it in an airport.

Rolling it out without a lost weekend

Don't try to do forty accounts in one sitting — attention fades and the last twenty get done badly. Go tier by tier, following your inventory. Do Tier 1 properly in one focused session: hardware keys, backup codes filed, recovery paths audited. Then batch Tier 2 and Tier 3 into short sessions, and record in the inventory which factor each account uses and where it lives.

That last column is the whole point. An account with 2FA enabled and no record of where the factor lives isn't protected — it's a lockout with a delay on it.

Related guides