Security

Multi-Factor Authentication

Sign-in using evidence from more than one factor category, such as a password and a device-held key. Methods vary in phishing resistance and recovery options, so protect backup methods and choose stronger options where available.

How it works

Multi-factor authentication combines distinct categories of evidence, commonly something known, something possessed or a biometric characteristic. Two-factor authentication is a form of MFA. Counting screens or questions is not enough: the checks need meaningfully different factors and a recovery process that does not quietly bypass their protection.

A practical example

An organization may require a password and a security key for administrator access, while another service uses an authenticator code. These choices have different resistance to phishing and different usability requirements. A biometric action on a device can unlock an authenticator locally without sending the biometric itself to the website.

What to check

Match the supported method to the account’s risk and users’ access needs. Review registration, lost-device recovery and replacement procedures, not only the sign-in screen. For managed services, verify whether MFA is enforced for all relevant accounts and remote access routes. Maintain a controlled emergency recovery arrangement rather than an undocumented exception.

Limits and safe use

MFA reduces dependence on passwords but is not universal protection against session theft, malicious software or deceptive approvals. Some methods are more phishing-resistant than others. Repeated unexpected prompts should be investigated instead of approved. A policy is effective only when the actual service configuration, enrollment and recovery procedures follow it.

Additional examples and checks

An email password leaks from another website. A separate security key can prevent that password alone from opening the mailbox, provided the recovery route is also protected.

Technical sources

← All glossary terms