IT glossary

MFA (Multi-factor authentication)

MFA, or multi-factor authentication, means proving who you are with more than one thing, usually a password plus a code or approval on your phone.

The two things are usually something you know, a password, plus something you have, such as a code or an approval prompt on your phone. Two-factor authentication, or 2FA, is the same idea with exactly two.

Why it matters to you

A stolen password on its own stops being enough. That single change removes the most common way organizations get broken into, which is not a sophisticated attack, it is somebody typing a real password that was phished, guessed, or bought.

It is also the first question on essentially every cyber-insurance renewal and client security questionnaire, and one of the few security controls that costs almost nothing to switch on.

Not all MFA is equal

  • App approval or a code from an authenticator app, good, and the practical default.
  • Number matching, where you type a number shown on screen into the app, better, because it stops people approving prompts by reflex.
  • A hardware key, strongest, and worth it for administrators and finance staff.
  • Codes by text message: better than nothing, but the weakest option, because phone numbers can be taken over.

The common failure

MFA switched on for most people, but not for the administrator accounts, the shared mailbox, or the one executive who found it annoying. Attackers look for exactly those. Coverage matters more than strength.

The service this relates to

See also

All terms

Still not sure what you actually need?

That is a normal place to start, and a 30-minute call usually settles it faster than more reading.