Google says it will start verifying users with 2FA enabled using a prompt on their phones, and will soon start automatically enabling 2FA for all users
The company is making some changes to encourage more people to adopt a key digital security mechanism. — Lorenzo Franceschi-Bicchierai
Context & Ripple Effects
Google had already been moving account authentication onto devices, first through phone-based login notifications and then by allowing compatible Android phones to serve as two-factor security keys. The new policy turns that device-centric approach from an opt-in tool into a default account setting.
Later coverage shows the same arc continuing from 2FA prompts toward default passkey creation, while Google Authenticator’s code-sync rollout raised questions about end-to-end encryption. The stakes are therefore not merely adoption: Google is increasingly defining both the default login method and the security properties around it.
First-order effects
- Google account holders with 2FA enabled will be verified through phone prompts, while users without it will be brought into 2FA automatically.
- Google gains a more consistent authentication flow across its account base, reducing reliance on users independently choosing and configuring a second factor.
Second-order effects
- Authentication-app providers and services built around alternative second factors face a higher bar: Google’s account defaults make its phone prompt the path most users encounter first.
- The shift increases the importance of Android devices in Google account security, building on their earlier role as security keys.
Third-order effects
- Google’s progression from phone prompts to default passkeys points to account security becoming a platform-controlled, device-bound experience rather than a user-assembled set of credentials.
- As providers centralize authentication defaults and code synchronization, encryption design becomes a product-governance issue, as the later Authenticator concerns illustrate.
The trend: Major platforms are moving authentication from optional user configuration toward default, device-mediated sign-in flows that culminate in passkeys.