Guide

How to Set Up Two-Factor Authentication on LinkedIn

Your LinkedIn account contains your professional history, connections, private messages, and in many cases job application activity. A compromised LinkedIn account can be used to send phishing messages to your network, damage your professional reputation, or scrape your contact information. Two-step verification significantly reduces the risk of unauthorised access.

How to Enable 2FA on LinkedIn

  1. Click your profile photo at the top right of linkedin.com and select Settings & Privacy.
  2. Click Sign in & security in the left menu.
  3. Click Two-step verification.
  4. Click the Set up button.
  5. Choose your verification method: Authenticator app or Phone number (SMS).
  6. For authenticator app: LinkedIn displays a QR code. Scan it with your authenticator app, then enter the 6-digit code to confirm. For SMS: enter your phone number and verify the code LinkedIn texts you.
  7. Click Verify and then Done. Two-step verification is now active.
Choose an authenticator app over SMS. LinkedIn accounts are frequently targeted by account takeover attempts. Authenticator apps are not vulnerable to SIM swapping and work without cellular connectivity.

LinkedIn's Two-Step Verification Methods

Authenticator App (Recommended)

LinkedIn works with any standard TOTP authenticator app. Google Authenticator, Authy, Microsoft Authenticator, 1Password, and Bitwarden all work correctly. After entering your password, LinkedIn asks for the 6-digit code currently shown in your app. The code refreshes every 30 seconds and works offline. This is the most secure option available on LinkedIn.

Phone Number (SMS)

LinkedIn can send a verification code by text message to your registered phone number. This is easier to set up but less secure than an authenticator app. If you are currently using SMS, consider switching to an authenticator app, especially if your account is connected to recruiters, clients, or has a large professional network.

Trusted Devices on LinkedIn

After successfully completing two-step verification, LinkedIn gives you the option to mark your current browser or device as trusted for 30 days. On a trusted device, LinkedIn will not ask for a verification code on every sign-in. Only mark your personal devices as trusted โ€” never shared or public computers.

LinkedIn Premium Accounts and 2FA

If you have LinkedIn Premium, your account has access to InMail credits, recruiter tools, and premium analytics. These features make a compromised Premium account more valuable to attackers and more costly for you to deal with. Two-step verification is especially important for Premium accounts.

LinkedIn 2FA for Business and Sales Navigator Accounts

LinkedIn's Sales Navigator and LinkedIn Recruiter products operate as part of your LinkedIn account rather than as separate logins. Two-step verification on your LinkedIn account automatically applies to any Premium products associated with it. If you use LinkedIn for business prospecting or talent acquisition, securing your account with 2FA also protects your business investment.

What to Do If You Are Locked Out of LinkedIn

If you cannot access your 2FA method, click Having trouble? on the verification screen. LinkedIn provides alternative sign-in options including email verification. If you cannot access the associated email either, LinkedIn's customer support can help verify your identity, though this process may take several business days.

Related Articles

Why Your LinkedIn Account Is More Valuable Than You Think

LinkedIn accounts are targeted not just for the account itself but for the professional network it represents. A compromised LinkedIn account can be used to send convincing phishing messages to your connections (who are more likely to trust a message from a known colleague), to impersonate you in business contexts, to access job applications or recruitment data, and โ€” for accounts with LinkedIn Premium or Recruiter access โ€” to conduct fraudulent hiring activities. Business email compromise (BEC) attacks frequently use LinkedIn to research targets before impersonating colleagues.

LinkedIn 2FA: Methods and Campaign Manager Impact

LinkedIn supports SMS and authenticator apps for 2FA. LinkedIn does not yet support hardware security keys. Use an authenticator app for stronger protection โ€” SMS is the weaker option, particularly for business users who may be more targeted than average. Note that if you use LinkedIn advertising through Campaign Manager, enabling 2FA may require you to re-authorise any marketing partner integrations. LinkedIn also warns that enabling 2FA logs you out of all existing sessions on all devices โ€” you will need to log back in on each device, completing the 2FA process on each.

What to Do When Changing Your Phone Number

Update your phone number in LinkedIn Settings before switching phones if you use SMS 2FA. If you lose access to your old number before updating, you will be locked out of your LinkedIn account if SMS is your only 2FA method. LinkedIn's account recovery for lost 2FA access requires contacting LinkedIn Support and demonstrating account ownership. Switching to an authenticator app avoids this phone-number dependency entirely.

Frequently Asked Questions

Does enabling LinkedIn 2FA log me out of all devices? Yes โ€” LinkedIn warns you about this during setup. All existing sessions on all devices are terminated when you enable 2FA. You will need to log back in on each device.

Does LinkedIn 2FA affect third-party apps connected to my account? Apps connected via LinkedIn OAuth continue to work with their existing access tokens. They will need to go through the OAuth flow again if their token expires, at which point your 2FA will be required to re-authorise.

Is LinkedIn 2FA mandatory? Not yet mandatory for personal accounts, but LinkedIn strongly recommends it and may require it for additional use cases in the future.