Apple Two-Step Verification Now Available for iMessage and FaceTime [Updated] - MacRumors
Skip to Content

Apple Two-Step Verification Now Available for iMessage and FaceTime [Updated]

Apple's two-step verification system now covers FaceTime and iMessage, reports The Guardian. Signing into an iMessage or FaceTime account protected by two-step verification will ask users to input an app specific password, which can only be obtained by logging in to an Apple ID account on the web with an authentication code, thereby preventing any unauthorized login attempts.

IMG_3365
Two-factor verification is an opt-in system that was first introduced in March of 2013 to increase the security of Apple ID accounts. Prior to today, a verification code was only required for making changes to an account, signing into iCloud, or making iTunes/App Store purchases from a new device.

Two-factor authentication for iCloud is a recent addition that was implemented in September following the breach of several celebrity iCloud accounts, leading to a slew of leaked photos. The hacking incident led Apple to improve the security of iCloud and it also prompted the company to send out security emails when a device is restored, iCloud is accessed, or a password change is attempted.

Last month, a Medium post highlighting some of the remaining shortcomings of two-factor authentication was shared by several technology sites, which may have inspired Apple to update the service to protect iMessage and FaceTime accounts. The post pointed out that it was still possible to log into iMessage, FaceTime, iTunes, the App Store, and into the website using an account with two-factor authentication enabled without being asked for a verification code.

It seems two-factor authentication for iMessage and FaceTime may still be rolling out to users, as MacRumors was able to log into iMessage and FaceTime accounts with two-factor authentication enabled without a code.

Update: Two-factor authentication for iMessage and FaceTime seems to be more widely available now, and it appears that logging into an account requires an app specific password rather than a code to prevent unauthorized entry attempts.

Popular Stories

Apple Wallet

iOS 27 Will Add Two New Apple Wallet Features to Your iPhone

Monday June 1, 2026 12:15 pm PDT by
Apple is set to unveil iOS 27 during its WWDC 2026 keynote on Monday, June 8, and the update will reportedly include two new Apple Wallet features. First, iOS 27 will reportedly let users create their own digital passes by scanning items like movie tickets, concert passes, and gym membership cards. Many apps already offer Apple Wallet passes, but now users will be able to create a custom...
HomePod mini and Apple TV Sage

New Apple TV and HomePod Mini Are 'Nearly Ready' to Launch, New Siri Remote Also Rumored

Sunday May 31, 2026 8:47 am PDT by
New models of the Apple TV 4K and HomePod mini are "nearly ready to go," according to the latest word from Bloomberg's Mark Gurman. Subscribe to the MacRumors YouTube channel for more videos. Both devices have been ready "for months," but Apple is holding off on launching them until the more personalized version of Siri is available, he said. "I am told the hardware for the next Apple TV...
Apple Foldable Thumb

First 'Confirmed' iPhone Ultra Color Allegedly Revealed in Leaked Image

Monday June 1, 2026 4:39 am PDT by
Apple is expected to launch its first foldable iPhone later this year. Rumors suggest the "iPhone Ultra" will come in two color options, and a leaker shared an image today that allegedly shows one of them. Posted on Weibo by the Chinese leaker known as Ice Universe, the image purportedly offers a first glimpse of Apple's foldable in white. The device is believed to have entered early mass...

Top Rated Comments

148 months ago
This is tooo complex!

Passcode, iCloud password, two-factor authentication, app specific password, recovery code, key chain passcoe..... This is way too complex. I have a background in IT and I cannot keep up with the complexity. I don't think the average use knows how to navigate through.

Apple has to give us something simpler. Maybe Apple Watch is the saviour?
Score: 13 Votes (Like | Disagree)
148 months ago
What I don't like is that this is compulsory. Annoying.
Score: 4 Votes (Like | Disagree)
Apple_Robert Avatar
148 months ago
Good move by Apple.
Score: 4 Votes (Like | Disagree)
148 months ago
Passcode, iCloud password, two-factor authentication, app specific password, recovery code, key chain passcoe..... This is way too complex. I have a background in IT and I cannot keep up with the complexity. I don't think the average use knows how to navigate through.

Apple has to give us something simpler. Maybe Apple Watch is the saviour?

This hits it on the head. As an IT professional you would love to recommend that everyone turn on 2-factor wherever it exists. However, the reality is that for the MAJORITY of users, the probability of them getting hacked is much smaller than the probability of them locking themselves out of their own account! It's unfortunate, but true, that even many technically savvy people are horrible at organization and record-keeping. They are so used to just being able to reset forgotten passwords at will, that they are at great risk of forfeiting any account that they choose to enable 2-factor on.

Password managers certainly go a long way towards optimal use of unique passwords. However, how many users do you know would actually know how to use their password manager of choice well. How many people do you know that if they enabled 2-factor for a given service like an AppleID, would take the time to customize their vault entry to include their 2-factor recovery key?

How many people do you know that understand that they will forfeit their purchases, email, iCloud, etc, forever if they enable 2-factor on their AppleID but then get locked out and don't know their recovery key?

For these reasons, in 2014 I still find it tough to recommend 2F for anyone that I don't know well enough to understand their technical and credential management aptitude. For the other 99%, I just try to get them interested in using a password manager instead.
Score: 3 Votes (Like | Disagree)
Small White Car Avatar
148 months ago
I don't see the point? What is there in FaceTime or iMessage I need to secure? It's not like my SSN is stored there.
Well, considering that banks are now using a text message as THEIR 2-factor authentication and the fact that texts sync with iMessage and... well you start to see the problem. Your life is becoming a web and entire thing is only as strong as its weakest point.
Score: 3 Votes (Like | Disagree)
148 months ago
Staying safe can be annoying, but the alternative can be a lot worse.:(

Yeah, someone could break into your phone and send an iMessage with one of the new emoticons that doesn't match your race, and then you could get sued for being racially insensitive. (colon, right parenthesis)
Score: 3 Votes (Like | Disagree)