Microsoft 365

Set Up Two-Step Verification on Your Microsoft Account (and App Passwords)

Published ✓ Verified ⏱️ 3 min read February 13, 2026 · by Ryan Bennett

You want a second layer of security on your Microsoft account, or you turned on two-step verification and now an old mail app or device keeps saying your password is wrong.

Why: two-step verification asks for two things to sign in — your password and a code (or an approval in an app). That’s great for security, but apps and devices that can’t show a code prompt (older phone mail apps, some games consoles) then fail with an “incorrect password” error. The fix for those is a one-time app password.

Fix 1: Turn on two-step verification

  1. Go to account.microsoft.com/security and sign in.
  2. Select Manage how I sign in (under the security/advanced security options).
  3. Find Two-step verification and choose Turn on.
  4. Follow the prompts — you’ll confirm a method (email, phone text, or the Microsoft Authenticator app, usually by scanning a QR code). Microsoft Authenticator is the smoothest because you just approve a notification instead of typing codes.
  5. Finish the wizard. Save any recovery code it offers somewhere safe — it gets you back in if you lose your phone.

From now on, signing in on a new device asks for your password plus a code/approval.

Fix 2: “Incorrect password” on an old app or device — create an app password

If a mail app on an older phone, an older Outlook, or a device like a game console rejects your password after you turned on two-step verification, it can’t handle the code step. Give it an app password instead.

  1. Go to account.microsoft.com/securityAdvanced security options.
  2. Scroll to the App passwords section and choose Create a new app password. (This section only appears once two-step verification is on.)
  3. Microsoft shows a long, random password. Copy it.
  4. In the app or device that was failing, enter this app password where you’d normally type your account password. You usually only enter it once on that device.

Each app password is single-use per device — if you need to sign that device in again later, just generate a fresh one. You don’t have to remember old ones.

Fix 3: Keep your security info current

Two-step verification only protects you if your methods still work:

  • On the Security page, confirm your recovery email, phone, and authenticator are all up to date.
  • Add a second method (e.g. authenticator and a phone) so losing one device doesn’t lock you out.
  • Keep the recovery code from setup — it’s your backup when no other method is available.

FAQ

Do I need app passwords for modern apps? No. Current apps (recent Outlook, the Microsoft 365 apps, modern browsers) handle two-step verification directly. App passwords are only for older apps/devices that can’t prompt for a code.

Where did the App passwords section go? It only shows up when two-step verification is turned on. Enable it first (Fix 1), then the section appears under Advanced security options.

I lost my phone and can’t get a code. Use your saved recovery code, or another method you set up. If you have none, you’ll have to recover the account via the recovery form — which is why a second method is worth adding now.

Is two-step verification the same as a passkey? No, but they’re related security options. This guide covers two-step verification; passkeys are a separate passwordless sign-in method on the same Security page.

Sources: Microsoft Support — How to use two-step verification with your Microsoft account · Microsoft Support — How to get and use app passwords

↑↓ navigate · ↵ open · Esc close See all results →