What Is 2FA (Two-Factor Authentication)?

Also called: Dual-factor authentication

Related problems: Accounts taken over with stolen or reused passwords; Cyber insurer or customer asking whether we use 2FA; Staff confused about which second step to set up; Not sure whether text-message codes are good enough

Two-factor authentication (2FA) is a way of signing in that requires two different kinds of proof before access is granted: typically something you know, such as a password, plus something you have, such as a phone or security key, or something you are, such as a fingerprint. It is the most common form of multi-factor authentication (MFA), which covers two or more factors. A stolen password alone is not enough to get into an account protected by 2FA, which is why insurers, auditors and customers ask about it.

At a glance

  • 2FA means exactly two factors from different categories: knowledge, possession or inherence (biometrics).
  • Common second factors are text-message or voice codes, one-time passwords (OTP) from an authenticator app, push prompts and hardware security keys.
  • Not all second factors are equal: SMS codes, app codes and push prompts can be phished; FIDO2 keys and passkeys are designed to resist it.
  • Two steps of the same kind, such as a password plus a security question, are not true 2FA.
  • Recovery and fallback methods often decide how strong 2FA really is.

What problem it solves

Passwords are reused, guessed, leaked in breaches and typed into fake login pages. Attacks such as credential stuffing work because a username and password are all an attacker needs. 2FA adds a second, independent requirement, so a leaked password on its own usually doesn’t open the account.

For a business, that cuts the most common route to email compromise, payment fraud and ransomware entry through remote access. It is also one of the first controls insurers, auditors and enterprise customers check for.

How it works

The user first proves one factor, usually by entering a password. The service then asks for a second factor from a different category:

  • Possession: a code. A one-time code sent by text or voice call, or generated by an authenticator app or hardware token. The user types it in.
  • Possession: a prompt. A push notification to an enrolled phone app, which the user approves, often by entering a number shown on the login screen.
  • Possession: a cryptographic key. A security key or passkey that signs a challenge from the service, usually after the user touches the key or unlocks it with a PIN or biometric.
  • Inherence. A fingerprint or face scan, usually checked locally on a device to unlock a key, rather than sent to the service.

In a business, 2FA is normally enforced by your identity provider (IdP), which decides which methods are allowed for which users and applications, and how often users must re-verify.

The factors must be independent. If a password and its one-time code end up on the same unprotected phone, or a help desk will reset the second factor on a phone call, the protection is weaker than it looks.

When it matters for buyers

  • At cyber insurance application or renewal. Expect questions about 2FA or MFA on email, remote access, administrator accounts and backups.
  • When a customer or auditor sends a security questionnaire. 2FA on staff accounts is a standard question.
  • When choosing methods. Moving from SMS to app-based or key-based methods raises security; requiring phishing-resistant MFA for admins and finance staff raises it further.
  • When planning for lost phones and keys. Recovery processes need strong identity checks, or attackers will use them as the way in.
  • When users complain about prompts. Excessive prompting trains people to approve without looking, which is what MFA fatigue attacks exploit.
  • For shared or kiosk devices. Staff who share terminals or can’t carry a personal phone may need security keys or other methods.

Questions to ask vendors

  • Which second-factor methods do you support, and can we disable SMS and voice for some or all users?
  • Do you support FIDO2 security keys and passkeys, and on which license tiers?
  • Does your push method use number matching or show sign-in context, and can we require it?
  • How are new users enrolled, and how do you stop an attacker from enrolling their own device?
  • What is the recovery process when a user loses their phone or key, and what identity checks does it use?
  • Can we report which users have which methods registered, for audits and insurance questionnaires?

How it differs from multi-factor authentication (MFA)

MFA is the broader term: two or more independent factors. 2FA is the specific case of exactly two. In practice, most workforce sign-ins described as MFA are 2FA, a password plus one other factor, and vendors and insurers often use the two terms interchangeably. The more useful question for a buyer is not two versus three factors but which kind of second factor is used, because that decides whether the sign-in can be phished. For controls around administrator accounts, where strong second factors matter most, see our privileged access management overview.

Frequently Asked Questions

Is 2FA the same as MFA?
2FA is a type of MFA. Multi-factor authentication means two or more factors; two-factor authentication means exactly two. In everyday use the terms are often used interchangeably, and most business sign-ins that are called MFA use two factors.
Is two-step verification the same as 2FA?
Often, but not strictly. Two-step verification describes two steps, which might both be the same kind of factor, such as a password followed by a security question. 2FA requires two different kinds of factor. Many services use the name two-step verification for what is, in practice, 2FA.
Is SMS 2FA still worth using?
It is better than a password alone, but it is one of the weaker second factors. Text-message codes can be intercepted or redirected through SIM swaps and can be typed into fake login pages. Many organizations keep SMS only as a fallback and move users to an authenticator app, a security key or passkeys.
Which second factor is the strongest?
Phishing-resistant methods, such as FIDO2 security keys and passkeys, are generally the strongest because they are bound to the genuine site. Authenticator app codes and push prompts are a step up from SMS but can still be relayed by a fake login page.
Do cyber insurers require 2FA?
Many insurance applications ask about MFA on email, remote access, backups and administrator accounts, and some ask which methods you use. Requirements vary by insurer and policy, so check your own application wording.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.