Skip to content

What is Multi-Factor Authentication (MFA)?

Cybersecurity & Compliance, explained by the engineers who build it. Definition, how it works, use cases and common questions.

MFA definition

Multi-factor authentication (MFA) is a security method that requires users to prove their identity with two or more independent factors before gaining access: something they know, such as a password; something they have, such as a phone or security key; or something they are, such as a fingerprint. It blocks most attacks using stolen passwords.

How does multi-factor authentication work?

After entering a password, the user must complete another check from a different category, such as approving a push notification, entering a code from an authenticator app or touching a hardware security key. Even if an attacker steals or guesses the password through phishing, a data breach or credential stuffing, they cannot log in without the second factor. Adaptive MFA adjusts requirements based on risk, asking for extra verification for new devices, unusual locations or sensitive actions.

Types of authentication factors and methods

MFA methods differ significantly in security and convenience, and attackers have adapted to weaker ones. Choosing the right methods for each group of users, such as stronger factors for administrators and finance staff, matters as much as enabling MFA at all. The common methods, roughly from weakest to strongest, are listed below.

  • SMS or voice codes: better than passwords alone, but vulnerable to SIM swapping and interception.
  • Email codes: convenient but only as secure as the email account.
  • Authenticator app codes (TOTP): apps like Google Authenticator or Microsoft Authenticator.
  • Push notifications with number matching to resist approval fatigue.
  • Hardware security keys using FIDO2, such as YubiKey.
  • Passkeys: FIDO2 credentials stored on devices and confirmed with biometrics.

What is phishing-resistant MFA?

Attackers now use phishing kits that proxy login pages in real time, capturing both the password and the one-time code as the victim enters them, or flood users with push requests until one is approved. Phishing-resistant methods, based on FIDO2 and WebAuthn standards, such as security keys and passkeys, cryptographically bind authentication to the genuine website domain, so they simply do not work on a fake site. Security agencies increasingly recommend these methods, especially for administrators and high-value accounts.

How to roll out MFA

Start with the accounts that matter most: email, identity provider, cloud consoles, source code repositories, VPN or remote access and finance systems. Centralize authentication through a single identity provider with single sign-on, so MFA is enforced consistently. Offer convenient methods, such as passkeys and push with number matching, provide backup codes and a secure recovery process, and remove legacy protocols that bypass MFA. Service accounts need separate controls such as short-lived credentials.

Communicate before enforcing, give users time to enroll, and monitor for accounts still without MFA. Help desk recovery procedures need strong identity verification, because attackers often target support staff to reset a victim's MFA. Track enrollment rates by department and follow up personally with teams that lag behind.

MFA in your own applications

Customer-facing applications benefit from MFA too, particularly for financial, health and admin functions. Identity platforms such as Auth0, Amazon Cognito, Firebase Authentication and Microsoft Entra External ID provide MFA and passkeys without building cryptography yourself. Nexzem implements MFA and passkey login in client applications, balancing security with sign-in friction for each type of user. Step-up prompts for risky actions keep everyday sign-in simple.

MFA: common questions

Something else on your mind? Ask a consultant and get a reply within one business day.

What is the difference between MFA and 2FA?

Two-factor authentication (2FA) uses exactly two factors, typically a password plus a code or device. Multi-factor authentication (MFA) means two or more factors, so 2FA is a type of MFA. In everyday use the terms are often interchangeable, since most MFA deployments use two factors.

Is SMS-based MFA safe?

SMS codes are much better than a password alone, but they are the weakest common MFA method. They can be intercepted through SIM swapping, where attackers convince a carrier to move a victim's number, and are easily phished. Use authenticator apps, passkeys or security keys where possible, especially for administrators and sensitive accounts.

Are passkeys a form of MFA?

Passkeys combine something you have, the device holding the private key, with something you are or know, the biometric or PIN that protects it. Because of this, many security frameworks treat passkeys as phishing-resistant multi-factor authentication in a single step, while also removing the need for passwords.

Keep exploring the cybersecurity & compliance glossary

Need MFA in your product?

A solutions consultant replies within one business day with next steps, a rough estimate and a suggested team.