- Customer Service tab.
- "Visit the Security Center" in the left column under Security Features
- "View your SafePass settings" under the Online Banking menu when you expand it.
- I assume at that point there's an "Add SafePassDevice" option. I already have my phone added. I remember when I added it there was a snafu and I had to call the BOA fraud hotline to get it added, but they did add it.
- Once you have a SafePass device (sms-capable mobile), under Current SafePass settings, "change these settings" and set it to require SafePass to log in to online banking.
I don't like SMS 2-factor. People need to stop pretending that mobile networks are secure. I want something that runs autonomously on my phone (OATH, e.g. Google Authenticator), or a separate HW token for higher security. However, the choice between no 2-factor and SMS 2-factor is a no-brainer if you have an SMS allowance on your plan.