About this tool
Weighted 15-step checklist to enable LinkedIn two-step verification, save recovery codes, clear old sessions and lock down profile discovery.
The LinkedIn 2FA Setup Guide is a weighted, 15-control checklist for locking down a LinkedIn account: two-step verification with an authenticator app, saved recovery codes, a verified primary email, clean sessions, and the visibility settings that decide who can find you. Each control carries a score share based on how much it blocks a real takeover, and four of them are marked critical, so the score stays capped at 69% until all four are done. It is aimed at anyone whose job search, client work or professional reputation lives on LinkedIn and who wants a definite finish line rather than a vague sense of being secure.
Open LinkedIn 2FA Setup Guide on AltFTool — it loads instantly in your browser.
Set a Target score (%) and work down the grouped checklist of 15 LinkedIn controls, ticking each one as you set it in your account.
Clear the four Critical controls first — the Hardening score will not rise above 69% while any of them is still open.
Read the Hardening score with Weighted points and the Do these next list, then press Copy result to save where you got to.
Controls are scored by takeover impact, so the password and second factor count for far more than a visibility toggle.
The score refuses to rise above 69% while any critical control is open, which stops a false sense of safety.
The checklist runs entirely in your browser and never asks for your LinkedIn password, phone number or a verification code.
Open Settings & Privacy > Sign in & security > Two-step verification, choose Set up, and pick Authenticator App instead of Phone. LinkedIn asks for your password, shows a QR code to scan into an authenticator app, and then displays single-use recovery codes that you should save immediately.
Yes, because SMS codes can be intercepted through a SIM swap, where an attacker persuades your mobile operator to move your number to their SIM. An authenticator app generates the code on your device using the TOTP standard, a 6-digit code refreshed every 30 seconds, so nothing travels over the phone network.
Sign in with one of the recovery codes LinkedIn gave you when you enabled two-step verification; each code works once. If you did not save them, you have to go through LinkedIn's identity verification, which typically means uploading a government ID and waiting for manual review, so save the codes before you need them.
LinkedIn supports passkeys, which appear under Sign in & security when your account and device are eligible. A passkey signs you in with your device unlock instead of a typed password and cannot be handed to a phishing site, because the browser will only release it to the genuine linkedin.com domain.