Multi-factor authentication (MFA) is a sign-in method that requires two or more independent proofs of identity before granting access, typically a password plus something the user has, such as a phone or security key, or something they are, such as a fingerprint. Because a stolen password alone is no longer enough, MFA blocks many of the most common account takeover attacks. It is now a baseline expectation for email, remote access and administrator accounts, and cyber insurers commonly ask whether it is in place.
At a glance
- MFA combines factors from different categories: something you know, something you have and something you are.
- Common second factors include authenticator app prompts, one-time codes, security keys, passkeys and biometrics.
- It sharply reduces risk from stolen or reused passwords, but weaker methods can still be phished or abused.
- Phishing-resistant methods such as FIDO2 security keys and passkeys are the strongest widely available option.
- MFA is usually enforced through an identity provider, alongside single sign-on and conditional access policies.
What problem it solves
Passwords get stolen through phishing, data breaches and malware, and people reuse them across sites, which fuels credential stuffing. With a password alone, anyone who has it can sign in as the user. Compromised email and remote access accounts are a common starting point for fraud, ransomware and data theft.
MFA adds a second, independent check. An attacker who has the password still needs the user’s phone, key or fingerprint, which stops most automated and opportunistic attacks. It also gives security teams a control they can require, report on and prove to auditors, customers and insurers.
How it works
Factors. Authentication factors fall into three categories: something you know (a password or PIN), something you have (a phone, smart card or hardware security key) and something you are (a fingerprint or face). MFA requires factors from at least two categories; two passwords would not count.
Sign-in flow. The user enters their first credential, then the system asks for a second: a one-time password (OTP) by text or app, a push approval in an authenticator app, a tap of a security key or a biometric check on a trusted device. Only when both succeed is access granted.
Central enforcement. Most organizations enforce MFA through an identity provider (IdP), so applications connected through single sign-on (SSO) get the same protection. Conditional access policies can ask for stronger verification when risk is higher, such as a new device, an unusual location or an admin task, and skip repeat prompts on trusted, managed devices.
Strength varies. Text-message codes can be intercepted or redirected by SIM swapping. Push approvals can be abused through MFA fatigue attacks, where users are bombarded with prompts until they approve one; number matching reduces this. Codes and pushes can also be relayed by fake login pages in real time. Phishing-resistant MFA built on FIDO2 and WebAuthn, including passkeys, ties the login to the genuine site so relayed attempts fail.
When it matters for buyers
- Cyber insurance applications and renewals. Insurers commonly ask about MFA for email, remote access, backups and privileged accounts, and answers can affect coverage.
- Compliance and customer requirements. Some frameworks, such as the CJIS Security Policy, and many security questionnaires expect MFA for specific kinds of access; requirements vary, so check the ones that apply to you.
- Privileged accounts. Administrators should use the strongest methods available, ideally combined with privileged access management (PAM).
- Legacy systems. Older applications and protocols may not support modern MFA and may need to be retired, placed behind a proxy or put behind single sign-on.
- Moving toward zero trust. MFA is a foundation of zero trust security, which verifies each access request rather than trusting the network.
For controls around administrator accounts, where strong MFA matters most, see our privileged access management overview.
Questions to ask vendors
- Which factors do you support, and do you support phishing-resistant methods such as FIDO2 keys and passkeys?
- Do push approvals use number matching or other protections against MFA fatigue?
- Can we enforce different methods for administrators, contractors and regular staff?
- Which of our applications, VPNs and legacy systems can you protect, and which need extra connectors or licensing?
- How are lost phones and keys handled, and how does the help desk verify users before resetting MFA?
- What reports show who is enrolled, which methods they use and where MFA was bypassed?
- Is MFA included in our current licensing, or does it require a higher tier?
How it differs from two-factor authentication (2FA)
Two-factor authentication (2FA) is the specific case of exactly two factors; MFA is the broader term for two or more. Most workforce sign-ins described as MFA are in fact 2FA, a password plus one other factor, and vendors and insurers often use the terms interchangeably. For buyers, the more useful question is not how many factors are used but which kind: a phishing-resistant security key is much stronger than a text-message code, even though both count as two-factor sign-in. A password manager helps people use strong, unique passwords but is not MFA by itself. Passwordless authentication may or may not be multi-factor: a passkey unlocked with a fingerprint combines two factors, while an emailed sign-in link does not.
