MFA Setup Guide for Everyone in New Zealand
A plain-English multi-factor authentication setup guide for New Zealanders, covering authenticator apps, passkeys, recovery codes, and safer sign-in.
Quick answer
Turn on multi-factor authentication for your email, banking, social media, school, and work accounts. Use a passkey, security key, or authenticator app when the service offers one; keep SMS as a fallback rather than your first choice. Save recovery codes somewhere separate from your phone.
MFA adds another check after your password. A stolen password alone is then less likely to give someone access to your account [1].
What should you protect first?
Start with the accounts that can reset or unlock everything else. Your primary email account comes first because password-reset messages for other services usually arrive there. Next, protect banking, cloud storage, school or work accounts, social media, and any password manager you use.
Do not wait until every account can be changed in one sitting. Protect the most important account today, then work through the rest over a few days. For help strengthening the password itself, read Passwords, Passphrases, and MFA: A Simple Guide.
Which MFA method should you choose?
A passkey or hardware security key is usually the strongest practical option because it is tied to the real website and resists common phishing attempts. An authenticator app is also a good choice: it creates a short-lived code on your device and does not rely on mobile reception.
SMS codes are still better than using a password alone, but mobile numbers can be moved through a SIM swap and text messages can be intercepted. Use SMS when it is the only method available, then upgrade if the service adds a stronger option.
How do you set up an authenticator app?
Open the security or sign-in settings for the account. Look for "two-step verification", "multi-factor authentication", or "two-factor authentication". Choose the authenticator-app option, then scan the QR code with an authenticator app on your phone. Enter the six-digit code shown by the app to confirm setup.
Do not photograph or share the QR code. It contains the secret used to generate future codes. If the site provides one-time recovery codes, download or print them and store them somewhere secure that is not on the same phone.
What should you do with recovery options?
Recovery settings are part of account security, not an afterthought. Check that your backup email belongs to you, remove old phone numbers, and store recovery codes in a password manager or locked physical location. Anyone who controls a weak recovery method may be able to bypass your stronger login.
Add a second trusted MFA method when the service allows it. For example, keep an authenticator app as the main method and a security key as backup. Do not make a shared school or work phone the only way several people can recover an account.
What if you receive an unexpected MFA prompt?
Deny it. An unexpected prompt can mean someone already knows your password and is trying to persuade you to approve their login. Change the password by visiting the service directly, review recent account activity, and sign out unknown sessions.
Never read a verification code to someone who contacts you. A genuine support worker should not ask for the code that proves you control the account. If the incident affects a school account, tell the school's IT contact or leadership promptly.
How can schools and families make MFA easier?
Explain the reason before the setup steps: MFA protects an account even when a password has leaked. Help each person configure their own method and confirm that recovery works before ending the session. Avoid collecting everyone's recovery codes in an unprotected spreadsheet.
Schools should begin with staff email and administrator accounts, then expand to learning and student-management platforms. Families can start with the shared recovery email and accounts used for purchases. Digital Safety Basics for Students in New Zealand gives younger users the wider account-safety context.
Knowledge check
Sources and references
[1] CERT NZ. (2025). Top 11 cyber security tips. https://www.cert.govt.nz/individuals/guides/top-11-cyber-security-tips/
[2] New Zealand Police. (2024). Internet scams, spam and fraud. https://www.police.govt.nz/advice/email-and-internet-safety/internet-scams-spam-and-fraud
Key takeaways
- Protect your primary email account first.
- Prefer a passkey, security key, or authenticator app over SMS.
- Store recovery codes away from the device used for MFA.
- Deny unexpected prompts and change the password directly through the service.
- Bottom line: Turn MFA on today, starting with email, and use the wider password guide if your passwords also need attention.
What to do next
- Review Passwords, Passphrases, and MFA: A Simple Guide.
- Help younger users with Digital Safety Basics for Students in New Zealand.
- Educators can use Cyber Security for New Zealand Educators for school-wide controls.
- Continue through the Resource Library.