---
title: "Best practices for Buffer account security"
description: "Enabling two-factor authentication (2FA)"
canonical_url: "https://support.buffer.com/articles/best-practices-for-buffer-account-security-GH1k1HJ9ws"
md_url: "https://support.buffer.com/articles/best-practices-for-buffer-account-security-GH1k1HJ9ws.md"
---
# Best practices for Buffer account security

## Enabling two-factor authentication (2FA)

Each user that you add to your Buffer organization will have their own unique login. To ensure the security of your accounts, we encourage you and your users to [enable two factor authentication](https://support.buffer.com/en-us/articles/using-two-factor-authentication-in-buffer-FClTl67lZB), which adds an extra layer of security to your Buffer account. When 2FA is applied, whenever you log into your account, you'll first be asked for your username and password, and then you'll be asked for a second authentication code.

Recovery codes are single-use, and you'll get an email anytime one is used, so be sure to save the new code after each use, and treat the email as a security alert if it wasn't you.

Two-factor authentication codes can be generated via an authentication app such as Google Authenticator or Authy (available on iOS and Android).

Admins on Team plans can also require 2FA for every member of their organization from their **Team Settings**. [Learn how to require 2FA for your team](https://support.buffer.com/en-us/articles/using-two-factor-authentication-in-buffer-FClTl67lZB).

:::info
**Note: **We recommend using an authentication app instead of SMS/text — if you're not in cellular reception (eg: working on an airplane, or in a remote area), your code will not reach you via SMS, but you can use authenticator apps whenever you're connected to wifi. Read more about authentication apps from [CNET here](https://www.cnet.com/tech/services-and-software/do-you-use-sms-for-two-factor-authentication-heres-why-you-shouldnt/).
:::

## Managing billing details

All Admins can manage billing details in your Buffer dashboard, so it’s best to be cautious about who is granted Admin permissions.

## Who has accessed my account?

While Buffer Customer Advocates can see the IP addresses of devices that logged in to your account up to two weeks ago, it's important to note that if someone is *currently* logged in, their information won't be visible.

If you believe someone currently has access to your account, immediately take these steps:

* **Change your password** via your account settings here: <https://account.buffer.com/>. This article explains more: [Changing your email address or password](https://support.buffer.com/en-us/articles/changing-your-email-address-or-password-in-buffer-ejQEaExPMV)

  * **Note:** The maximum password length is 128 characters.
* **Enable two-factor authentication** (2FA) for an additional layer of security. You can do that from your account settings here: <https://publish.buffer.com/settings>. This article explains how to do this: [Enabling two factor authentication](https://support.buffer.com/en-us/articles/using-two-factor-authentication-in-buffer-FClTl67lZB)
