Your email, social media, artist dashboards, website and cloud storage may contain everything from unreleased music to financial information.
A password alone is not enough protection for accounts that important.
Two-factor authentication (2FA) adds another form of verification before someone can log in. Even if somebody gets your password, they still have another hurdle to clear.
It only takes a few minutes to set up, and it can save you from a much bigger headache later.
What is two-factor authentication?
Two-factor authentication uses two different ways to prove that you are really you.
Those usually come from three categories:
- something you know, such as a password
- something you have, such as your phone or a physical security key
- something you are, such as your fingerprint or face
You may also see platforms call this multi-factor authentication (MFA) or 2-Step Verification. The names vary, but the goal is the same: make a stolen password less useful to somebody else.
Start with the accounts that can unlock everything else
You should eventually protect every important account that offers 2FA. However, some deserve to move to the front of the line.
Start with:
- your primary email account
- your password manager
- social media accounts
- artist and label dashboards
- your distributor account
- cloud storage
- your website and domain registrar
- banking, payment and accounting accounts
Your email should be especially high on the list.
Think about how many websites let you reset a forgotten password by sending a link to your email. If someone controls that inbox, they may be able to work their way into other accounts from there.
Choose the strongest option available
Not every form of 2FA is equally secure.
If a platform gives you several choices, a good general order is:
- Passkey or security key: These are among the strongest options because they are designed to resist phishing.
- Authenticator app: An app generates a temporary code or approves a login from a device you control.
- Text or email code: Still much better than having no second factor, but generally the weakest of these options.
A passkey is a newer way to sign in using a device you control, often with your fingerprint, face or device PIN instead of a traditional password.
A security key is a small physical device that proves you have the actual key when you log in.
Phishing is an attempt to trick you into giving your login information to a fake website or person pretending to be legitimate. Passkeys and compatible security keys are particularly useful because they are much harder to use on an impostor website by mistake.
If those options are not available, an authenticator app is still a strong practical choice.
And if the only option is a text message, use it. We are not going to let perfect become the enemy of significantly better.
How to set up 2FA
The exact wording changes from platform to platform, but the process is usually pretty similar.
- Open your security settings. Look for Security, Sign-In & Security, Two-Factor Authentication, Multi-Factor Authentication or 2-Step Verification.
- Choose your method. If the platform offers a passkey, security key or authenticator app, consider one of those before SMS.
- Follow the setup instructions. An authenticator app may ask you to scan a QR code. A security key may need to be inserted or tapped against your device.
- Complete the test. Enter the requested code or approve the verification so the platform knows everything is connected correctly.
- Save your recovery options. Do this before you close the page.
Then log out and log back in once.
It is better to find out now that you misunderstood a step than six months from now when you desperately need access.
Do not ignore the backup codes
Many platforms give you backup codes, one-time codes that can get you back into the account if you lose access to your normal authentication method.
Save them.
Seriously.
Put them somewhere secure, such as a reputable password manager or another protected location you can still reach if your phone disappears.
Do not leave the only copy sitting casually in your email, a shared document or your camera roll.
If the platform lets you register more than one secure authentication method, that can also give you another way back in.
Do not approve a login you did not start
Some authentication apps send a push notification asking you to approve a login.
If you are not trying to log in, do not approve it.
An attacker who already has your password may repeatedly send authentication requests hoping you eventually tap “Approve” just to make them stop.
Deny the request. Then change the password and review the account for suspicious activity.
Also, never give somebody a current authentication code because they claim to be from support. The whole point of that code is proving that you have the second factor.
Use separate access for your team when possible
Artists rarely operate completely alone.
Managers, labels, publicists, distributors and other team members may all need access to different platforms. Whenever a service allows it, give each person their own account or team permission instead of passing around one username, password and authentication code.
That way, somebody can leave the team without forcing everyone else to change a shared login.
It also makes it much easier to know who actually has access.
Spotify for Artists is one example of a platform built around artist and label teams. Our guide to setting up Spotify for Artists explains how artists, managers and labels can be added to the appropriate team.
2FA does not replace a good password
You still need a different password for every important account.
If you reuse the same password everywhere and one service gets compromised, attackers can try that same email and password on your other accounts.
A password manager can make unique passwords much easier to maintain because you do not have to memorize every one of them.
Long passwords are generally more useful than trying to remember whether this particular website required three capital letters, two symbols and your firstborn child.
Review your security once in a while
Setting up 2FA is not something you need to obsess over every Tuesday.
Still, it is worth reviewing important accounts periodically.
Check:
- which devices are signed in
- which people still have team access
- whether your recovery email and phone number are current
- whether your backup codes are still available
- whether the platform now offers a stronger authentication option
Security tools continue to improve. An account you protected with text-message codes a few years ago may now offer an authenticator app, passkey or security key.
A few minutes now is easier than account recovery later
Most of this is not complicated.
Protect the important accounts first. Use the strongest authentication method the platform gives you. Save the backup codes. Give team members their own access when possible. And never approve a login you did not request.
You have enough things competing for your attention as an artist.
Trying to convince a social network that you really do own the account somebody stole should not become one of them.
