Facebook Account Security in 2026: What Is Actually on the Recovery Screen
Trusted contacts are gone, the settings moved into Accounts Center, and passkeys arrived. A current checklist for locking down a Facebook account you own or have just taken over, with every screen named.
Avery BennettMost Facebook security checklists on the web still tell you to set up trusted contacts. That advice was good once. It is now the single most expensive sentence you can follow, because you will spend five minutes looking for a switch that is not there, conclude you must have missed it, and move on believing you have a recovery route that does not exist.
So this starts with what Meta actually offers today, screen by screen, and only then gets to the habits.
Trusted contacts are gone. Here is what replaced them
The feature let you nominate friends who could be sent a recovery code on your behalf. It is no longer in the product and no longer in the documentation. Meta's own Recover an Account hub lists eleven articles and not one of them mentions trusted contacts or friends helping you log in. The Security Tips and Features hub lists twenty-two items and does not mention them either. The help article ID that used to hold the explanation now redirects to a generic account security page.
What sits in that gap instead is a set of things you configure in advance:
- Recovery login codes. Facebook issues ten of them, each usable once, and you have to have two-factor authentication switched on before the option appears at all. Print them or put them in a password manager. This is the closest replacement for what trusted contacts used to do, and it is the one most people never turn on.
- An authenticator app, rather than SMS. Codes generated on your device are not exposed to a SIM swap.
- A hardware security key, if the account is worth protecting properly. Facebook supports FIDO2 keys as a second factor.
- A passkey, which is a different thing again and covered below.
- A current recovery email and phone number, which are what the identity confirmation flow leans on when you cannot get in.
- Security Checkup, Meta's own guided pass over all of the above. If you only do one thing on an account you just took over, do this one.
The settings moved, and they are mid-migration
Guides written before 2024 send you to Settings and then Security and Login. That menu is gone. Password, two-factor authentication and recovery codes now live under Accounts Center: profile picture, then Settings and Privacy, then Settings, then Accounts Center, then Password and Security.
There is a wrinkle worth knowing before you go hunting. Meta is gradually moving people from Accounts Center to Meta Accounts and says plainly that you may see either one as the place to manage your settings. If the menu you find does not match the guide you are reading, that is usually why, and not a sign that something is wrong with the account.
Session review moved too. "Where you're logged in" still exists under that exact name, but it is now reached through the Activity Log rather than the old security menu: profile picture, then Settings and Privacy, then Activity Log, then Where you're logged in.
Passkeys, and why they are not the same as two-factor
Facebook added passkeys in 2025 and they change the login rather than adding a step to it. Once you create one, you do not enter your password to reach Facebook or Messenger at all: a fingerprint, a face scan or a device PIN does the whole job. Meta's requirements are a computer running at least Windows 10, macOS Ventura or ChromeOS 109, or a hardware key that supports FIDO2, with Chrome 109, Safari 16, Edge 109 or Firefox 122 upward.
Treat a passkey as a convenience on devices only you touch, not as a substitute for the recovery set above. It lives on a device. Devices get lost, and the ten recovery codes are what you will reach for when one does.
Login environment still matters more than the password
Facebook's automated systems weigh how and where an account signs in, not only whether the password was right. A new device, a new country and a fresh browser fingerprint arriving together is unusual even with correct credentials, and it is a common trigger for an extra verification screen.
Accounts with real posting history and consistent login patterns generally meet less friction than ones created yesterday. That is a pattern, not a rule, and Meta does not publish how the signals are weighted, so treat anyone who quotes you a percentage on it with suspicion. What you can control is consistency: one device or browser profile per account, one connection per account, and no rotating several accounts through a single shared session. Teams that hop between accounts in one browser are a reliable way to get those accounts flagged as a group.
Team access, which is where most business accounts actually get lost
Business use rarely means one person holding all the keys, and sharing one login across a team is the version of that with no audit trail and no way to revoke anything. Business Manager and Page roles let you hand out admin, advertiser, editor or analyst access separately.
Review the list at least once a quarter and immediately whenever somebody leaves. Give the narrowest role that does the job. The point is not tidiness: it is that one compromised team member should not be able to take the whole account with them.
A setup checklist you can actually verify
Every row below names a real screen, so you can confirm each one rather than assume it.
| Setting | Where it lives now | Done looks like |
|---|---|---|
| Two-factor authentication | Accounts Center, Password and Security | Authenticator app, not SMS only |
| Recovery login codes | Same screen, under Additional Methods | Ten codes saved offline |
| Passkey | Accounts Center, Password and Security, Passkey | Created on devices only you use |
| Recovery email and phone | Accounts Center, contact info | Both current and both reachable |
| Session review | Activity Log, Where you're logged in | Checked on a schedule, not after a scare |
| Team access | Business Manager roles | Individual roles, no shared login |
If you find a session you do not recognise, log it out, change the password, then look at connected apps for anything unfamiliar. Do all three in the same sitting. Waiting is what turns a single bad login into a week of unnoticed access.
What the marketplace listings actually tell you
Security features are not evenly advertised, and the listing text is the only place they are declared before you buy. Across the live Facebook account listings on HstockPlus, most say something about two-factor authentication, a little over half mention a cookie, and a smaller group mention a token or a matching user agent. Only a handful mention a passkey at all, and interestingly those few are on the Facebook shelf rather than the email shelves, where the same term appears nowhere. Not one listing anywhere mentions profile lock.
The practical reading is that "2FA" in a listing title usually means the seller holds a second factor, which is a thing you will need to replace with your own on day one. Compare what each listing says it includes before committing, since suppliers differ on this more than on price.
Facebook accounts across a wide range of ages and formats are listed by independent suppliers on the marketplace, and the same security baseline applies to Instagram accounts run alongside them.
One note on the proxy shelf
Advice to buy a residential proxy for each account is common, including in the earlier version of this article, and it deserves a correction rather than a repeat. The site's proxy shelf is 83 live listings, and by title text more than a third of them are consumer VPN subscriptions rather than proxies. A consumer VPN is close to the opposite of what a multi-account setup needs, because it puts you on a shared exit address alongside everyone else on that server. The residential subcategory is small, twenty listings, and a couple of those describe server or datacenter address ranges despite where they sit. Read the listing text rather than the shelf name, and if per-account address stability is what you are buying, confirm the listing says so.
Meta's Security Tips and Features hub is the authoritative index for everything above, and its Business Help Center covers the role and permission side. Both change faster than any article about them, this one included.


