Guide

How to Set Up Two-Factor Authentication on LinkedIn

Your LinkedIn account contains your professional history, connections, private messages, and in many cases job application activity. A compromised LinkedIn account can be used to send phishing messages to your network, damage your professional reputation, or scrape your contact information. Two-step verification significantly reduces the risk of unauthorised access.

How to Enable 2FA on LinkedIn

  1. Click your profile photo at the top right of linkedin.com and select Settings & Privacy.
  2. Click Sign in & security in the left menu.
  3. Click Two-step verification.
  4. Click the Set up button.
  5. Choose your verification method: Authenticator app or Phone number (SMS).
  6. For authenticator app: LinkedIn displays a QR code. Scan it with your authenticator app, then enter the 6-digit code to confirm. For SMS: enter your phone number and verify the code LinkedIn texts you.
  7. Click Verify and then Done. Two-step verification is now active.
Choose an authenticator app over SMS. LinkedIn accounts are frequently targeted by account takeover attempts. Authenticator apps are not vulnerable to SIM swapping and work without cellular connectivity.

LinkedIn's Two-Step Verification Methods

Authenticator App (Recommended)

LinkedIn works with any standard TOTP authenticator app. Google Authenticator, Authy, Microsoft Authenticator, 1Password, and Bitwarden all work correctly. After entering your password, LinkedIn asks for the 6-digit code currently shown in your app. The code refreshes every 30 seconds and works offline. This is the most secure option available on LinkedIn.

Phone Number (SMS)

LinkedIn can send a verification code by text message to your registered phone number. This is easier to set up but less secure than an authenticator app. If you are currently using SMS, consider switching to an authenticator app, especially if your account is connected to recruiters, clients, or has a large professional network.

Trusted Devices on LinkedIn

After successfully completing two-step verification, LinkedIn gives you the option to mark your current browser or device as trusted for 30 days. On a trusted device, LinkedIn will not ask for a verification code on every sign-in. Only mark your personal devices as trusted โ€” never shared or public computers.

LinkedIn Premium Accounts and 2FA

If you have LinkedIn Premium, your account has access to InMail credits, recruiter tools, and premium analytics. These features make a compromised Premium account more valuable to attackers and more costly for you to deal with. Two-step verification is especially important for Premium accounts.

LinkedIn 2FA for Business and Sales Navigator Accounts

LinkedIn's Sales Navigator and LinkedIn Recruiter products operate as part of your LinkedIn account rather than as separate logins. Two-step verification on your LinkedIn account automatically applies to any Premium products associated with it. If you use LinkedIn for business prospecting or talent acquisition, securing your account with 2FA also protects your business investment.

What to Do If You Are Locked Out of LinkedIn

If you cannot access your 2FA method, click Having trouble? on the verification screen. LinkedIn provides alternative sign-in options including email verification. If you cannot access the associated email either, LinkedIn's customer support can help verify your identity, though this process may take several business days.

Troubleshooting LinkedIn Two-Step Verification

If you are not receiving SMS codes, check that your phone number is still correct under Settings & Privacy โ†’ Sign in & security โ†’ Two-step verification, and confirm your mobile carrier delivers short-code messages from LinkedIn. If your authenticator code is rejected, synchronise your phone's clock โ€” TOTP codes rely on accurate time, so enable automatic date and time in your phone's settings. If you changed phones, you need to add LinkedIn to your new authenticator app; if you can no longer access the old app, use the Having trouble? flow on the sign-in screen, which offers verification through your email address. To switch from SMS to an authenticator app without turning 2FA off, open Two-step verification, choose the option to change method, and scan the new QR code. Keep your recovery email address up to date under Settings & Privacy โ†’ Sign in & security โ†’ Email addresses, because it is the fastest way back into your account if you lose access to both your phone and your authenticator app.

LinkedIn Account Security Beyond 2FA

Two-step verification works best alongside the other security settings LinkedIn provides. Open Settings & Privacy โ†’ Sign in & security โ†’ Where you're signed in and review the list of active sessions; sign out of any device or browser you do not recognise, which is a common sign of a hijacked session. LinkedIn also lets you choose whether to receive sign-in alerts by email and push notification โ€” keep these on so you are notified the moment an unknown login is attempted. Avoid marking shared or public computers as trusted for 30 days, since other users of that machine could then sign in without a code. Finally, enable 2FA on the email address tied to your LinkedIn account as well: an attacker who controls your email can reset your LinkedIn password and intercept the verification messages LinkedIn sends to it.

How a LinkedIn Account Takeover Actually Happens

Most LinkedIn takeovers start with a leaked password. Attackers buy credential lists from data breaches on other sites โ€” where users recycled the same password โ€” and run them against LinkedIn's login page in an automated process called credential stuffing. Without two-step verification, a match is all it takes: the attacker signs in, changes the password, disables sign-in alerts, and begins messaging your connections with fake job offers or investment links. Because those messages come from your real profile, colleagues and recruiters are far more likely to open them, which is why hijacked LinkedIn accounts are a favourite tool for spreading malware and running financial scams.

Two-step verification changes the maths of this attack. The moment the attacker tries to sign in with your password, LinkedIn demands a code they do not have, and โ€” if you have sign-in notifications enabled โ€” you receive an alert that someone attempted to access your account. You can then change your password before anything harmful happens. In short, 2FA protects not just your profile but everyone in your professional network who might otherwise trust a message from you.

Common Mistakes to Avoid When Setting Up LinkedIn 2FA

  • Choosing SMS when you own a smartphone โ€” SMS codes can be hijacked through SIM-swap social engineering, and they stop arriving when you travel with roaming off.
  • Marking your work computer as a trusted device โ€” if your employer manages that machine, you are effectively trusting everyone with access to it for 30 days.
  • Leaving an old phone number on file โ€” when your carrier reassigns that number, future SMS codes and recovery messages go to a stranger.
  • Relying on a work email as your only recovery mailbox โ€” many people lose LinkedIn access after changing jobs because the address is deactivated before they remember to update it.
  • Deleting sign-in alert emails โ€” filter them into your inbox instead; they are the earliest warning of a hijack attempt.

If any of these describe you, fix them before you need to rely on 2FA: update your phone number and recovery email under Settings & Privacy โ†’ Sign in & security, and only mark devices you personally control as trusted.

What to Expect on Your First Few Sign-Ins With 2FA

During the first 30 days after enabling two-step verification, LinkedIn may ask for a code more often than you expect. This is normal: the trust window starts fresh on every device you mark as trusted, and browsers that clear cookies on exit โ€” private windows and privacy-focused browsers in particular โ€” will request a code on each visit.

Signing in through the LinkedIn mobile app works slightly differently. After you enter the code once, the app keeps you signed in, but the prompt returns if you switch between accounts, reinstall the app, or log out. LinkedIn's 2FA also applies across linkedin.com, the mobile app, LinkedIn Learning, and SlideShare: a code requested on one surface is not shared with another, so expect to verify again when you move between them.

Why the Email on Your LinkedIn Account Is the Real Key

Password reset links and most verification messages are sent to the email address on your account. An attacker who controls that mailbox can reset your LinkedIn password and read the recovery messages LinkedIn sends โ€” which effectively bypasses the 2FA prompt. Enabling two-factor authentication on the email provider itself, whether Gmail, Outlook, or another service, closes this gap.

Add at least two email addresses to your LinkedIn account so a compromised or lost mailbox does not lock you out, and remove any address you no longer control, such as a university account or an old employer domain. Keep your recovery email and phone number up to date in the same settings area where you manage two-step verification.

Does 2FA Slow Down Your LinkedIn Experience?

On trusted devices you will not notice 2FA at all โ€” LinkedIn remembers them for 30 days. The only extra step appears when you clear cookies, switch browsers, or sign in on a new phone. Weigh that against the cost of a hijacked profile: lost connections, deleted posts, and a reputation hit that follows you into future job applications. For most users the 30-day trust window makes two-step verification effectively invisible.

Related Articles