SMS codes are better than nothing, but they are vulnerable to SIM swapping, number recycling, and phishing. Upgrading your most important logins to an authenticator app or passkeys will materially reduce your risk—but only if you migrate carefully. This guide shows you exactly how to move from SMS to stronger factors without getting locked out, using a sensible order of operations, checklists, and recovery safeguards.
What You’re Upgrading From—and To
SMS codes (old method): One-time codes sent by text. Vulnerable to SIM swaps, malware that reads texts, and delayed delivery when traveling or out of coverage.
Authenticator apps (new method): Time-based one-time passwords (TOTP) that refresh every 30 seconds (e.g., 1Password, Microsoft Authenticator, Aegis, Authy legacy accounts, Google Authenticator with cloud sync disabled unless you need it). Works offline, not tied to your phone number.
Passkeys and security keys (new method): Phishing-resistant sign-in using built-in device biometrics (platform passkeys) or hardware security keys (FIDO2/U2F like YubiKey). No codes to type; the website verifies your device cryptographically.
Many services let you enable more than one factor type at once. The safest path is to add new methods first, verify them from a second device, then remove SMS as a fallback—not before.
Before You Start: Build a Safety Net
Prepare these essentials before changing anything:
- Primary email secured: Turn on MFA for your main email first (use authenticator or passkey). If someone controls your email, they can reset other accounts.
- Two authenticator options: Choose a reputable authenticator app. If it supports encrypted backups or multi-device sync, enable it; otherwise plan secure manual backups (see below).
- Two hardware keys (recommended): If you’ll use passkeys or security keys, have two physical keys or at least one key plus a platform passkey on two devices.
- Offline recovery storage: A secure place for recovery codes: a locked safe, a fireproof envelope, or a password manager’s secure notes. Do not store solely in email or photos.
- Spare unlocked device: A second device (phone, tablet, or computer) to test new sign-ins before you remove SMS.
The Right Order: Migrate Your Identity Backbone First
Migrate in layers so you always have a way back in:
- Primary email account(s) (Gmail, Outlook, iCloud)
- Password manager (if you use one)
- Mobile carrier and Apple/Google account (phone number control)
- Financial and crypto (banks, brokerages, wallets, tax)
- Shopping and payments (Amazon, PayPal, Venmo, Apple Pay, Google Pay)
- Critical work and productivity (Microsoft/Google Workspace, cloud storage)
- Social, gaming, and everything else
Within each category, move one account at a time, fully verify, then proceed.
Step-by-Step: Migrate a Single Account Safely
- Log in from a trusted device and network. Use your usual device and home network to reduce fraud flags.
- Confirm you can still receive the current SMS codes. If not, recover access first before attempting changes.
- Add a second factor (don’t remove SMS yet):
- If using an authenticator app: Find the site’s Security or 2-Step Verification page. Choose Authenticator App, scan the QR code, and enter the 6-digit code to confirm.
- If using passkeys or hardware keys: Choose Add Security Key or Add Passkey. Register your device biometrics or tap your hardware key. Add a second key or second device if available.
- Generate and store recovery codes. Download or print recovery codes now. Label them clearly and store offline. If offered, add a backup email or phone you control.
- Test on a second device or browser profile. Sign out and sign in again using only the new method. Ensure you can approve the login without SMS.
- Set at least two independent methods. Aim for one authenticator app plus one passkey or hardware key—or two different authenticators if that’s all the site supports.
- Reorder or remove SMS as a fallback. Once you’ve proven the new method works on two devices, either move SMS to last place or remove it entirely if the site allows.
- Update your records. Note the date, methods enabled, where recovery codes live, and any backup device or key tied to the account.
Choosing Between Authenticators, Passkeys, and Security Keys
Use this quick decision guide:
- Best phishing resistance: Passkeys or FIDO2 hardware keys. Choose this for financial and primary email accounts.
- Broadest compatibility: Authenticator app (TOTP). Nearly all services support it.
- Travel and offline reliability: Authenticator app codes work without signal; hardware keys work offline too.
- Shared access or family recovery: Some password managers support shared passkeys or code-sharing workflows. Use with caution and clear rules.
Backup and Recovery That Actually Works
Lockouts usually happen because the owner removed SMS before creating reliable backups. Prevent that with layered backups:
- Recovery codes: Treat them like master keys. Store offline and label by account name and date.
- Second authenticator device: Install the same app on a second device and enroll it where allowed. If multi-device isn’t supported, export encrypted TOTP backups or capture the QR secret during setup and store it securely.
- Two hardware keys or one key plus platform passkeys: Register at least two factors that don’t live on the same device.
- Emergency contacts: Some services allow trusted contacts or recovery emails. Add at least one you control long-term.
Special Considerations for Common Services
- Gmail/Google Account: Enable 2-Step Verification, add a passkey, add at least one security key, store backup codes, and verify you can sign in on a second device before removing SMS. Keep your recovery email current.
- Apple ID: Add multiple trusted devices. Consider a security key set if you can manage physical keys. Ensure you know your device passcodes and recovery contact if configured.
- Microsoft Account: Use the Microsoft Authenticator or passkeys. Add a second sign-in method and store recovery codes.
- Banks and brokerages: Many still rely on SMS. If authenticator or security keys are offered, enroll them. If not, keep SMS but harden your mobile account with a carrier port freeze and account PIN.
- Password managers: Add two second factors before you remove SMS. Losing access here cascades to everything else.
Protect Your Phone Number Even After You Migrate
You may still keep SMS as a last-resort recovery method on some accounts. Reduce phone-number risk anyway:
- Set a strong carrier PIN and port-out lock. Contact your carrier to add a number transfer/port freeze.
- Minimize where your number is public. Remove or obfuscate it from social profiles and data broker sites where possible.
- Watch for SIM-swap warning signs: Sudden loss of cell service, password reset emails, or unfamiliar logins.
Testing and Verification Checklist
After migrating each account, confirm the following:
- I can sign in on a second device or browser using the new method only.
- I have at least two independent factors enrolled (e.g., authenticator + passkey).
- Recovery codes are saved offline and labeled.
- SMS is removed or demoted to last priority.
- My notes are updated with the date and methods enabled.
What If Something Goes Wrong?
- Lost authenticator device: Use your second device, recovery codes, or security key. Re-enroll a new authenticator and revoke the lost one.
- Lost hardware key(s): Use your backup key or a platform passkey. Immediately remove the missing key from your account.
- Travel or new phone setup: Test sign-in before you leave or switch phones. Export encrypted authenticator backups if supported, and carry a spare security key in a separate bag.
- Account won’t accept your new method: Temporarily keep SMS while you contact support. Document screenshots of errors and the date you attempted migration.
Documentation You Should Keep
Maintain a simple, private record of your security setup:
- Accounts you’ve migrated, with dates.
- Which methods are enabled (authenticator, passkeys, hardware keys).
- Where recovery codes are stored.
- Serial numbers or labels for hardware keys.
- Carrier port freeze/PIN status and last verification date.
Security Hygiene That Makes Migration Safer
- Update passwords first. Change weak or reused passwords before you add new second factors.
- Use a password manager. Store unique passwords and notes about your MFA configuration.
- Beware of phishing during setup. Navigate to security pages by typing the URL, not by clicking links in emails or texts.
- Turn on sign-in alerts. Many services can notify you of new logins or factor changes—enable those alerts.
When to Keep SMS (For Now)
Some accounts still don’t support anything better. When SMS is your only choice:
- Harden your mobile account (PIN + port freeze).
- Ensure the account also has strong password hygiene and alerts.
- Periodically check if the service adds authenticator or passkey support, then migrate promptly.
Financial Identity Monitoring as a Backstop
Strengthening your login factors greatly reduces account-takeover risk, but breaches and identity fraud can still happen. Continuous monitoring can help you catch unauthorized credit or financial activity early while you tighten your authentication. If you want a single place to track credit, report changes, and identity-related activity, consider a reputable monitoring solution such as SmartCredit as an added safety net.
Quick Migration Blueprint
- Secure your primary email and password manager with authenticator or passkeys first.
- Add at least two independent new methods (authenticator + passkey or two keys).
- Generate and store recovery codes offline.
- Test sign-in on a second device using only the new method.
- Demote or remove SMS once the new methods are proven.
- Document everything and repeat for the next account.
Frequently Asked Questions
Will removing SMS lock me out?
Not if you add and test new methods first and keep recovery codes. Never remove SMS until you have at least two working alternatives verified on a second device.
Are passkeys better than authenticator apps?
Passkeys are more phishing-resistant and easier to use. Authenticators offer broad compatibility. Many people use both for redundancy.
Do I need hardware keys?
They’re strongly recommended for primary email, password managers, and financial accounts. Keep a spare key registered and stored separately.
What about losing my phone?
Have a second enrolled device, security key, or recovery codes. That’s why you test cross-device sign-ins before removing SMS.
Conclusion
Moving from SMS codes to authenticators or passkeys is one of the highest-impact upgrades you can make for your digital privacy. The key to avoiding lockouts is simple: add first, test on a second device, back up with recovery codes and a spare factor, then remove SMS. Work in the right order—email and password manager first, then financial and other critical accounts—and document as you go. With a careful, one-account-at-a-time approach, you’ll end up with stronger, simpler sign-ins and much lower risk from SIM swaps, phishing, and account takeovers.
Good to Know
Move one account at a time and test sign-in on two devices before deleting any old method. Keep recovery codes offline and confirm at least two independent factors work before you consider the migration complete.