Topic

Multi-factor authentication

Multi-factor authentication requires evidence from more than one authentication-factor category before granting access.

At a glance

Common abbreviation
MFA
Core idea
Use distinct authentication factor types

Overview

Multi-factor authentication strengthens account access by requiring different kinds of evidence rather than merely asking for two copies of the same kind. Common factor categories include something a person knows, something a person possesses, and something inherent to the person. The strength of a particular method depends on how those factors are implemented and how resistant they are to phishing or account recovery abuse.

Two steps are not always two factors

Entering a password twice or answering two knowledge questions does not create two-factor authentication because both rely on the same knowledge category. MFA requires independent factor types so compromise of one type does not automatically satisfy the complete login requirement.

Phishing resistance varies

One-time codes improve protection over password-only access but can still be captured by convincing phishing flows. Hardware-backed and cryptographic authenticators can provide stronger phishing resistance when the service and client verify the legitimate destination as part of authentication.

Sources and review

MOOR's explanatory text is supported by the following source links.

  1. Digital Identity Guidelines: Authentication and Authenticator Management — NIST
  2. Secure Our World account security guidance — CISA

Browse MOOR Knowledge