P2 intermediate Identity

Passkeys & 2FA for Sensitive Accounts

Replaces: Password-only auth, SMS 2FA

Enable passkeys and TOTP-based two-factor authentication on every sensitive account and never use SMS 2FA.

account-takeoverdata-breach

Phase

Account Setup + Migration — free or low-cost, 30-60 min

General

Enable passkeys where supported (Google, Microsoft, GitHub, etc.). For TOTP 2FA: Aegis (Android, FOSS, F-Droid) or Bitwarden Authenticator. Never use SMS 2FA for sensitive accounts if TOTP is available.

Prerequisites

Password manager must be set up first to store and organize credentials.