Skip to content

Glossary · Security

Multi-Factor Authentication

A login security control requiring two or more verification factors so a stolen password alone is not sufficient to compromise an account.

Browse all definitions

In detail

Multi-Factor Authentication (MFA) requires a user to combine two or more of three factors, something they know (password or PIN), something they have (authenticator app, hardware token, SMS code, passkey), or something they are (biometric). MFA dramatically reduces account compromise risk because an attacker who steals a password still cannot log in without the second factor. TOTP authenticator apps (Google Authenticator, Authy, 1Password) and hardware keys (YubiKey) are considered stronger than SMS MFA, which is vulnerable to SIM swapping. The ACSC Essential Eight includes MFA as one of its eight mandated controls.

Sources & further reading

Check the source, not just the summary

Apply the definition

Want to talk through how this applies to your business?

Start with the decision in front of you. We will help map the fit.

Straight answers · no pitch deck · no commitment