A password is one lock on your front door. Two-factor authentication, often shortened to 2FA, is a second lock that needs a different key, usually your phone. If someone gets hold of your password, whether through a data breach or a scam, that second lock is what stops them getting in anyway.
What it actually looks like
Once it's turned on, logging in from a new device asks for a short code, usually sent by text or generated in an app, in addition to your password. It adds perhaps ten seconds to logging in somewhere new, and nothing at all on devices you use every day.
A password is something you know. Two-factor authentication adds something you have. A scammer needs both.
Where to turn it on first
Start with your email account. It's the one account that can be used to reset almost every other password you own, which makes it the most valuable lock in the house. Your bank and any account with saved payment details come next.
Text message or an app?
A text message code is far better than nothing, and perfectly fine for most people. An authenticator app, like Google Authenticator or Microsoft Authenticator, is slightly stronger and doesn't rely on phone signal. Either is a genuine improvement over a password alone.
Free apps worth grabbing today
Both Google Authenticator and Microsoft Authenticator are free. See the full list of password and account tools.