How it works
Multi-factor authentication combines distinct categories of evidence, commonly something known, something possessed or a biometric characteristic. Two-factor authentication is a form of MFA. Counting screens or questions is not enough: the checks need meaningfully different factors and a recovery process that does not quietly bypass their protection.
A practical example
An organization may require a password and a security key for administrator access, while another service uses an authenticator code. These choices have different resistance to phishing and different usability requirements. A biometric action on a device can unlock an authenticator locally without sending the biometric itself to the website.
What to check
Match the supported method to the account’s risk and users’ access needs. Review registration, lost-device recovery and replacement procedures, not only the sign-in screen. For managed services, verify whether MFA is enforced for all relevant accounts and remote access routes. Maintain a controlled emergency recovery arrangement rather than an undocumented exception.
Limits and safe use
MFA reduces dependence on passwords but is not universal protection against session theft, malicious software or deceptive approvals. Some methods are more phishing-resistant than others. Repeated unexpected prompts should be investigated instead of approved. A policy is effective only when the actual service configuration, enrollment and recovery procedures follow it.
Additional examples and checks
An email password leaks from another website. A separate security key can prevent that password alone from opening the mailbox, provided the recovery route is also protected.