Security

A little setup now gives you more control over your accounts

Passwords, multifactor authentication and passkeys: choose protection for important accounts and prepare a way to recover access.

The CloudCity teamPublished 2 min read

Your main email account can reset the passwords of many other services. Losing control of it can therefore affect your website, invoices and documents. Start account protection with email and administrator access rather than the application you use least. Multifactor authentication adds another check, but choosing the method and planning recovery matter just as much as switching it on.

Understand what the second step checks

A password is something you know. An authenticator app, a device or a security key adds separate evidence. Two passwords are not two different factors. A text message code can be better than no additional check, but it carries particular risks, including takeover of the phone number. When a service offers more phishing-resistant methods, compare those before accepting the default option.

When a passkey helps

A passkey uses cryptography and is tied to the service for which it was created. It can reduce the risk of handing a secret to a fake login page. The practical experience depends on the device and provider: some passkeys synchronise, while others stay on physical hardware. Check what happens when you replace a phone and whether authorised administrators can recover access if the person who configured it is unavailable.

Plan recovery before an incident

Keep recovery codes in a protected location separate from the phone used for authentication. Do not post them in the company chat. If the service supports a second method, configure a backup. For a critical account, test signing in from another device before closing the last working session. Strong protection should not make the business depend on one phone or one individual.

Reject requests you did not initiate

An unexpected login notification is not something to approve just to make it disappear. Reject it and check account activity. Attackers may send repeated prompts until someone approves automatically. Never read a code to an unexpected caller claiming to be support. Initiate contact through an official channel yourself and treat requests for authentication secrets as something requiring independent verification.

Organise access for the team

Give each colleague a separate account with appropriate permissions. Shared accounts make it harder to remove access or understand who changed something. Record who owns critical accounts, who can recover them and how those rights change when a contractor leaves. Review this list after team changes. Initial setup is the beginning of account management, not a task that can be forgotten permanently.

Sources and further reading

A CloudCity editorial guide informed by the documentation below. Check the official source for rules and procedures that may change.

Back to the blog