Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is MFA (multi-factor authentication)?

DefinitionMFA (multi-factor authentication) is a login method that requires two or more factors from different categories, such as something you know (password), something you have (token or phone) and something you are (biometrics), to confirm the identity of whoever is signing in.

How it works

A password alone can be guessed, reused from a breach or captured through phishing. MFA adds proof of a different kind, so a stolen password is not enough on its own to get in. Factors fall into three categories:

  • Knowledge: password, PIN or secret answer.
  • Possession: authenticator app, physical security key, card or a phone that receives a code.
  • Inherence: fingerprint, facial recognition or another biometric trait.

Two passwords are not MFA, because they are the same type of factor. 2FA (two-factor authentication) is the specific case of MFA with exactly two factors.

Not all MFA is equal

SMS codes are better than no second factor, but they are the weakest method: they can be intercepted or diverted through fraudulent SIM swaps. Push notifications suffer from so-called MFA fatigue, where the attacker sends approval requests repeatedly until the person accepts one. CISA recommends prioritizing phishing-resistant methods, such as security keys and passkeys based on FIDO2/WebAuthn, which bind authentication to the legitimate site.

In practice

MFA should be mandatory first where impact is highest: email, remote access, VPN, cloud consoles, administrative accounts and financial systems. It greatly reduces the risk of stolen credentials but does not eliminate it: session cookies captured by malware can bypass the login. That is why MFA works best combined with privileged access management (PAM), monitoring of anomalous logins and a Zero Trust strategy.

Network Secure helps assess and define access controls, including MFA, within GRC programs.

Frequently asked questions

What is the difference between MFA and 2FA?

2FA uses exactly two factors; MFA uses two or more. Every 2FA is a type of MFA.

Is SMS-based MFA secure?

It is better than a password alone, but it is the weakest method, since the code can be intercepted or diverted. Whenever possible, prefer an authenticator app or FIDO2 keys/passkeys, which resist phishing.

Go deeper