Google is simplifying configuration process two-factor authentication (2FA). Instead of entering your phone number first to activate 2FA, you can now add a “second step method” to your account, like an authenticator app or hardware security key, to set things up.
This should make it safer to enable 2FA as it allows you to avoid using less secure SMS verification. You can choose to enter a time-based one-time password through apps like Google Authenticator or follow the steps to bind a hardware security key.
Google offers two options for binding a security key, including registering a FIDO1 credential with the hardware key or assigning an access key to one. If you have a Workspace account linked to an organization and want to use a passkey, you may still need to sign in with a password, depending on your organization’s settings.