A password can be guessed, reused or leaked. A second factor is what makes that stop mattering.
If someone learns your password, they can sign in as you. That is the whole problem, and no amount of complexity requirements fixes it.
Two kinds of second factor
An authenticator app generates a code from a secret only your phone and the server know. An SMS sends a code to your number. The app is stronger, because a phone number can be moved to someone else’s SIM.

If you only turn on one thing this year, make it the authenticator app.
Keep your recovery codes somewhere that is not your phone. They are the way back in when the phone is lost.