Start with the email accounts your AI tools sign in through, then go tool by tool: ChatGPT (Settings, then Security and login), your Google or Microsoft account's security page for Gemini and Copilot, Zapier (Security and data) and Make (Profile, 2FA tab). Claude signs you in through Google or an emailed link, so securing that account secures Claude.
Order matters more than people expect. Most AI tools offer "Continue with Google" or "Continue with Microsoft", so the email account behind them is the real front door: a code on ChatGPT does little if the Gmail account that can reset it runs on a password alone. Two-factor authentication (2FA, also called multi-factor authentication or two-step verification) means a second proof after the password, such as a code from an app, a tap on a phone prompt or a passkey. Allow about ten minutes per person per account.
The sign-in chain: secure the email accounts first
Before touching any AI tool, write down how each person actually signs in to it. For a small team that's a 20-minute job in a spreadsheet, and it usually changes the order of work. Secure the accounts in this sequence:
- Email accounts. Google Workspace, Microsoft 365, or the personal Gmail or Outlook address someone uses for work. These receive password resets and, in Claude's case, the login link itself.
- The accounts behind "Continue with…" buttons. Usually the same Google or Microsoft accounts, but check: some staff sign in with Apple or a personal address.
- AI tools with their own password. ChatGPT accounts created with an email and password, Zapier and Make.
- Everything else with AI inside. Design, transcription, CRM and scheduling tools. Search each one's help pages for "two-factor"; if a tool has none, sign in through a Google or Microsoft account that does.
One illustration of why the order matters. A pet shop owner listed her tools and found that ChatGPT, Claude, Canva and Zapier all used "Continue with Google" on a single Gmail address, the same one that received the card terminal's receipts. Turning on 2-Step Verification for that one account protected four AI tools in about eight minutes. Left on a password alone, one phished password would have opened all four, plus every connection those tools had to her shop's files.
Where each AI tool keeps its two-factor setting
These paths were checked on each vendor's own help pages in September 2026. Menus move, so if a label differs slightly, search the tool's settings for "security".
| Tool | Where to turn it on | Can an admin force it on staff? |
|---|---|---|
| ChatGPT (and the OpenAI API) | Settings, Security and login, Multi-factor authentication | Not at workspace level; only through single sign-on with your identity provider |
| Claude | No separate setting: protect the Google or email account you sign in with | Team and Enterprise can use single sign-on |
| Gemini (Google account) | Google Account, Security & sign-in, Turn on 2-Step Verification | Yes, Workspace admins can enforce it |
| Copilot (Microsoft account) | account.microsoft.com/security, Manage how I sign in, Two-step verification | Yes, for Microsoft 365 business accounts |
| Zapier | Settings, Security and data, Two-Factor Authentication | No, each member sets it up |
| Make | Profile icon, Profile, 2FA tab, Enable | Yes, but only on Enterprise |
ChatGPT two-factor authentication
In ChatGPT, open Settings, choose Security and login, and pick a method under Multi-factor authentication. OpenAI's MFA help page lists an authenticator app (you scan a QR code and type the six-digit code it shows), push notifications to a trusted device, a text message by SMS or WhatsApp, and a passkey. One setup covers both ChatGPT and OpenAI's API platform, which matters if the same login holds your API keys. OpenAI notes that the options you see vary with your device, account type and how the account was created. The catch for teams: MFA can't currently be enforced across a ChatGPT workspace. If you need it compulsory, route sign-in through single sign-on and enforce MFA in Google Workspace or Microsoft Entra; our tutorial on setting up single sign-on for your team's AI tools covers that route.
Claude
Claude doesn't use a password of its own. Its help centre says you sign in with Google or with a secure link sent to your email, and that you can't create a dedicated Claude password. So there's no separate 2FA switch to find: the protection is whatever guards that Google account or inbox. On Team and Enterprise plans, admins can put sign-in behind single sign-on; Team plans can also verify the company domain and block new personal accounts on it, while claiming existing accounts is Enterprise-only.
Gemini and other Google accounts
Open your Google Account, choose Security & sign-in, and under "How you sign in to Google" select Turn on 2-Step Verification. Google's setup page lists passkeys, hardware security keys, Google prompts, Google Authenticator codes, SMS or voice codes, and a set of 8-digit backup codes. On Workspace, an admin can enforce it for everyone or for chosen groups from the Admin console under Security, Authentication, 2-step verification, and restrict which methods are allowed. Google now enforces it on administrator accounts anyway.
Copilot and Microsoft accounts
For a personal Microsoft account, go to account.microsoft.com/security, choose Manage how I sign in, then turn on Two-step verification under Additional security. Microsoft says it is phasing out SMS as a sign-in and recovery method for personal accounts, so use the Microsoft Authenticator app. Business accounts on Microsoft 365 are different: security defaults, which make every user register for MFA with an authenticator app, are on by default for tenants created after October 2019. Microsoft Learn shows how to check: in the Microsoft Entra admin centre, Identity, Overview, then the Properties tab and the Security defaults section. Finer rules through Conditional Access need Entra ID P1, which Business Premium includes.
Zapier and Make
Zapier: Settings, then Security and data under My account, then Two-Factor Authentication and Setup Two-Factor Authentication. You scan a barcode, type the code, and get 10 recovery codes; paid plans can add an emergency phone. Zapier's help page is blunt that owners and admins can't enforce 2FA for members, so each person does their own. Make: click your profile icon, choose Profile, open the 2FA tab and select Enable, then store the one-time recovery passwords somewhere other than your phone. Make Enterprise customers can switch on Enforce 2FA in their organisation settings, but that only covers people signing in with a Make email and password, not Google or single sign-on users.
Picking the second step for each person
Not every method is equal, and the right one depends on what the account can do.
| Method | Stops a fake sign-in page? | Best for | Watch out for |
|---|---|---|---|
| Passkey or hardware security key | Yes, it won't work on a lookalike site | Owners, admins, anyone with billing access | Register two, such as a phone passkey plus a spare key in the safe |
| Authenticator app codes or push prompts | Partly: a fake page can still ask for the code | Most staff | Codes live on one phone; move them before a phone is replaced |
| SMS or WhatsApp code | No, and numbers can be hijacked | A stopgap for tools with nothing better | Shared or personal numbers; Microsoft is phasing SMS out for personal accounts |
| Recovery or backup codes | Not a daily method | Emergencies only | Must be stored away from the phone they back up |
A sensible default for a small team: passkeys or a security key for the owner and whoever administers email, an authenticator app for everyone else, and SMS only where a tool offers nothing stronger. Push prompts need one rule taught out loud: a prompt you didn't cause means someone already has your password, so deny it and change the password straight away.
An optician's practice, account by account
As an illustration, consider an optician's practice with six staff: two optometrists, three people on dispensing and reception, and a practice manager who runs the automations. Their inventory came to eleven setups, because some tools ride on the Google sign-in:
| Account | People | Signs in with | Setups needed |
|---|---|---|---|
| Google Workspace (Gmail, Drive, Gemini) | 6 | Own password | 6 |
| ChatGPT Business | 2 | Email and password | 2 |
| Claude Pro | 1 | Continue with Google | 0, covered by Workspace |
| Canva | 4 | Continue with Google | 0, covered by Workspace |
| Zapier | 1 | Email and password | 1 |
| Make | 1 | Email and password | 1 |
| Microsoft account on the owner's laptop (Copilot) | 1 | Own password | 1 |
The sum: eleven setups at about ten minutes each is 110 minutes, plus 30 minutes for the owner to enforce 2-Step Verification in the Google Admin console and 20 minutes to build the recovery register below. Two hours 40 minutes in total, spread over two quiet afternoons. The five Claude and Canva sign-ins needed no work of their own once Workspace was enforced, which is the chain from the first section paying off.
Their first attempt went wrong in a way worth copying from. The owner set up Zapier's authenticator on her own phone, although the practice manager builds and fixes the Zaps. When an appointment-reminder Zap failed on a Friday evening, the manager couldn't sign in until Monday and 30 patients missed their reminder texts. The fix was to move the authenticator to the manager's phone and put the recovery codes in the practice's shared password vault, so the owner could still get in if the manager was away.
The recovery-code register they ended up with
| Account | Holder | Second step | Recovery codes kept in | Last checked |
|---|---|---|---|---|
| Google Workspace admin | Owner | Security key plus phone passkey | Sealed envelope in the safe; owner's private vault | Sep 2026 |
| ChatGPT Business (owner) | Owner | Authenticator app | Owner's private vault | Sep 2026 |
| ChatGPT Business (manager) | Practice manager | Authenticator app | Manager's private vault | Sep 2026 |
| Zapier | Practice manager | Authenticator app | Shared admin vault, 10 codes, none used | Sep 2026 |
| Make | Practice manager | Authenticator app | Shared admin vault | Sep 2026 |
| Microsoft account | Owner | Microsoft Authenticator | Owner's private vault | Sep 2026 |
"Last checked" means someone opened the entry, confirmed the codes are readable and noted how many remain unused. Recovery codes work once each, so you check them rather than test them. Where the vault lives, and how to share it without sharing logins, is covered in sharing AI tool logins safely with a password manager.
A rollout message for staff
People resist 2FA when it arrives as a surprise at 9am on a busy day. Give notice, a time limit and a person to ask. A message you can adapt:
Hi [first name],
From Thursday at 5pm, every AI tool we use at work will ask for a
second step when you sign in, as well as your password.
Before then, please:
1. Install Google Authenticator or Microsoft Authenticator on your phone.
2. Follow the one-page steps in the shared folder for each tool you use
(for you: Google Workspace and ChatGPT).
3. Save your recovery codes in your vault in the password manager,
not in your phone's notes.
It takes about 15 minutes. [Manager's first name] will be at the front
desk from 4 to 5pm on Wednesday to help anyone who gets stuck.
If your phone ever shows a sign-in prompt you didn't start, tap Deny
and tell [Manager's first name] straight away.
What to fix before sending: name only the tools that person uses, because a list of six tools they've never opened gets ignored. If you're switching on enforcement in Make, time it outside working hours: its help page warns that people without 2FA are signed out immediately, and suggests telling the team 24 to 48 hours ahead. Google Workspace enforcement deserves the same notice.
Lockouts and leaks: three mistakes worth avoiding
The traded-in phone. A garden centre supervisor swapped her phone for a new one and handed the old one back to the shop without moving her authenticator app. Her Zapier recovery codes were in a note on the same old phone. Zapier's own warning applies here: lose both the device and the codes and the account is gone for good, along with every Zap in it. The routine that prevents it: before any phone is replaced, move the authenticator accounts across, then sign in to each tool once on the new phone before wiping the old one.
Approving a prompt out of habit. Push prompts are convenient, and that's the problem. Someone who has stolen a password can trigger prompts late in the evening and wait for a tired "Approve". The illustrative case is a dispensing assistant who approved a Google prompt at 11pm because it "looked routine". The next morning a filter forwarding invoices to an outside address had appeared in the practice's shared inbox. Teach the deny-and-report rule, and give admins passkeys, which can't be approved from a sofa.
Assuming the admin switch covers everyone. In ChatGPT Business and Zapier, admins can't force 2FA, so a rollout there depends on each person finishing it. Ask everyone to send a screenshot of the security page showing the method switched on, and tick it off in the register. Without that step, the one account left unprotected is usually the one belonging to the busiest person.
Proving it's on, then keeping it on
- Test each account from a private browser window. Sign in; you should be asked for the second step. If you aren't, the setting didn't save or a trusted-device option is hiding it.
- Collect the screenshots for tools where admins can't see or enforce the setting.
- Check the admin views you do have. In Google Workspace, confirm enforcement is on for the right groups; in Microsoft 365, confirm security defaults or your Conditional Access policy is on.
- Put two dates in the calendar: a quarterly ten-minute review of the register, and a check at every staff change, which our offboarding checklist for AI tools and shared accounts builds in.
- Add new tools to the register the day someone signs up, not at the next review. New AI tools arrive faster than quarterly reviews.
What a second step won't protect
Two-factor authentication guards the sign-in page, and that's all. It doesn't cancel sessions already signed in on a lost laptop, so after a scare use the tool's option to sign out other devices where it has one, and change the password. It doesn't cover API keys or the connections an AI tool already holds to your Drive, inbox or CRM, which keep working whatever happens to the password; review those with a check of which apps can access your business accounts. And it can't make a shared login safe. If three people use one account, the second step ends up on one phone or in a group chat, and you lose any record of who did what. The better fix is separate seats, and our tutorial on setting up company AI accounts instead of personal logins explains how to move people across.
Two-factor authentication on AI tools: follow-up questions
What happens if I lose the phone with my authenticator app on it?
You sign in with a recovery or backup code instead, then set the authenticator up again on the new phone. That only works if the codes were stored somewhere other than the lost phone. Zapier says plainly that losing both your device and your recovery codes means permanently losing access to the account, so treat the codes like a spare door key kept off the premises.
Do passkeys replace two-factor authentication?
In practice they do the same job more safely. Google says signing in with a passkey skips the separate second step because it already proves you hold the device, and ChatGPT lets you add a passkey as one of your multi-factor methods. A passkey can't be typed into a fake sign-in page, which is the main way codes get stolen. Register two, so losing one device doesn't lock you out.
Should the business own the phone that receives the codes?
For accounts the business depends on, ideally yes, or at least the codes should sit in a business password manager rather than on one person's personal phone. If someone leaves suddenly, a personal phone walks out with them. For each person's own accounts, their own phone is fine, as long as their recovery codes are stored where the business can reach them.
Further reads
- AI Security Risks for Small Businesses and How to Close Them — The wider set of AI security risks and the order to close them.
- How to Train Staff to Spot AI-Written Phishing Emails — The phishing emails that try to steal passwords and codes.
- AI Security Checklist Before Connecting Tools to Email and Files — Checks to run before connecting AI tools to email and files.
- How to Spot Fake AI Apps and Risky Browser Extensions — Fake AI apps and extensions that bypass a good sign-in.
- Microsoft 365 Business Premium vs Standard for AI Security — When Conditional Access is worth the Business Premium upgrade.
- Business Data Backup Checklist Before You Connect AI Tools — Back up what matters before new tools get access.
- How to Prepare Your Small Business for AI Agents — Six things to have ready before an AI agent acts for you, with an approval table, a photography studio's four-week prep and a checklist.
- How to Onboard New Hires Onto Your AI Tools and Rules — A first-month plan for new starters on your AI tools: accounts before day one, one-page rules, buddy-checked tasks and a sign-off for wider access.
- Is ChatGPT Safe for Business Use? Risks, Settings and Plan Choice — The five real risks of using ChatGPT at work, the settings that fix most of them, and which plan fits a sole trader, a small team or a clinic.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OpenAI help pages (Managing multi-factor authentication; Passkeys; Advanced Account Security), Claude help pages (Log in to your Claude account; Set up single sign-on), Google Account Help (Turn on 2-Step Verification) and Google Workspace Admin Help (Deploy 2-Step Verification), Microsoft Support (two-step verification for a Microsoft account), Microsoft Learn (Set up multifactor authentication for users), Zapier Help (Set up two-factor authentication), Make help pages (Two-factor authentication; Two-factor authentication enforcement).