Two-factor authentication (2FA) is a way of signing in that requires two different kinds of proof before access is granted: typically something you know, such as a password, plus something you have, such as a phone or security key, or something you are, such as a fingerprint. It is the most common form of multi-factor authentication (MFA), which covers two or more factors. A stolen password alone is not enough to get into an account protected by 2FA, which is why insurers, auditors and customers ask about it.
At a glance
- 2FA means exactly two factors from different categories: knowledge, possession or inherence (biometrics).
- Common second factors are text-message or voice codes, one-time passwords (OTP) from an authenticator app, push prompts and hardware security keys.
- Not all second factors are equal: SMS codes, app codes and push prompts can be phished; FIDO2 keys and passkeys are designed to resist it.
- Two steps of the same kind, such as a password plus a security question, are not true 2FA.
- Recovery and fallback methods often decide how strong 2FA really is.
What problem it solves
Passwords are reused, guessed, leaked in breaches and typed into fake login pages. Attacks such as credential stuffing work because a username and password are all an attacker needs. 2FA adds a second, independent requirement, so a leaked password on its own usually doesn’t open the account.
For a business, that cuts the most common route to email compromise, payment fraud and ransomware entry through remote access. It is also one of the first controls insurers, auditors and enterprise customers check for.
How it works
The user first proves one factor, usually by entering a password. The service then asks for a second factor from a different category:
- Possession: a code. A one-time code sent by text or voice call, or generated by an authenticator app or hardware token. The user types it in.
- Possession: a prompt. A push notification to an enrolled phone app, which the user approves, often by entering a number shown on the login screen.
- Possession: a cryptographic key. A security key or passkey that signs a challenge from the service, usually after the user touches the key or unlocks it with a PIN or biometric.
- Inherence. A fingerprint or face scan, usually checked locally on a device to unlock a key, rather than sent to the service.
In a business, 2FA is normally enforced by your identity provider (IdP), which decides which methods are allowed for which users and applications, and how often users must re-verify.
The factors must be independent. If a password and its one-time code end up on the same unprotected phone, or a help desk will reset the second factor on a phone call, the protection is weaker than it looks.
When it matters for buyers
- At cyber insurance application or renewal. Expect questions about 2FA or MFA on email, remote access, administrator accounts and backups.
- When a customer or auditor sends a security questionnaire. 2FA on staff accounts is a standard question.
- When choosing methods. Moving from SMS to app-based or key-based methods raises security; requiring phishing-resistant MFA for admins and finance staff raises it further.
- When planning for lost phones and keys. Recovery processes need strong identity checks, or attackers will use them as the way in.
- When users complain about prompts. Excessive prompting trains people to approve without looking, which is what MFA fatigue attacks exploit.
- For shared or kiosk devices. Staff who share terminals or can’t carry a personal phone may need security keys or other methods.
Questions to ask vendors
- Which second-factor methods do you support, and can we disable SMS and voice for some or all users?
- Do you support FIDO2 security keys and passkeys, and on which license tiers?
- Does your push method use number matching or show sign-in context, and can we require it?
- How are new users enrolled, and how do you stop an attacker from enrolling their own device?
- What is the recovery process when a user loses their phone or key, and what identity checks does it use?
- Can we report which users have which methods registered, for audits and insurance questionnaires?
How it differs from multi-factor authentication (MFA)
MFA is the broader term: two or more independent factors. 2FA is the specific case of exactly two. In practice, most workforce sign-ins described as MFA are 2FA, a password plus one other factor, and vendors and insurers often use the two terms interchangeably. The more useful question for a buyer is not two versus three factors but which kind of second factor is used, because that decides whether the sign-in can be phished. For controls around administrator accounts, where strong second factors matter most, see our privileged access management overview.
