Reviewed and updated in October 2026.
Passwords alone no longer protect an account. Multi-Factor Authentication adds a second line of defense that most organizations can switch on quickly. Here is what it is, how it works, and which variants actually stop today's phishing attacks.
Multi-Factor Authentication (MFA) is a sign-in method that requires two or more independent pieces of evidence, called factors, before access is granted: something you know, something you have, or something you are. A stolen password alone is then not enough to take over an account. Phishing-resistant MFA, such as FIDO2 security keys, passkeys or smart cards, goes further and cannot be relayed through a fake login page.
MFA strengthens authentication by adding another layer of security. It does not rely on credentials alone, since these may be compromised, but also asks for complementary evidence that only the user can provide at that moment.
There are several variants depending on the number and type of factors (two-factor authentication or 2FA, two-step verification and so on), but they all rest on the same basic concept.
Applied to mobility, MFA verifies that whoever tries to access a corporate resource, on-premises or in the cloud, is in fact who they claim to be, by asking for a second (and possibly third) factor after the initial authentication.
MFA is part of daily life. At an ATM, the user needs the card (physical, or virtual on a phone or watch) and must know the PIN to complete the transaction. If you have ever used a token to establish a VPN connection to your company network, you have already used MFA.
Things have evolved since then. With mobile devices at the center of everything, there are options that need no easy-to-lose piece of plastic. MFA providers know that a phone or wearable is rarely left at home, so they built several ways to make authentication easy:
Many people know these methods from setting up accounts with Microsoft, Google or Apple. The same methods are available for companies to implement.
Since this article first appeared, attackers have learned to defeat the weaker methods. Fake login pages relay codes in real time, SIM swaps redirect SMS, and repeated push prompts wear users down until they approve one ("MFA fatigue"). In its fact sheet Implementing Phishing-Resistant MFA (October 2022), CISA therefore ranks the methods:
NIST points the same way. SP 800-63B-4, finalized in July 2025, requires verifiers at authentication assurance level 2 (AAL2) to offer at least one phishing-resistant option and requires phishing resistance at AAL3. Out-of-band codes via the phone network are a "restricted" authenticator. Synced passkeys are accepted at AAL2, but not at AAL3. How passkeys work in practice is explained in Goodbye Passwords, Hello Passkeys, and how attackers target identities in How to Thwart Phishing Attacks with Enhanced Identity Management.
You may not have to choose at all: most identity providers (IdPs), such as Microsoft Entra ID or Google Workspace, already include MFA. If not, vendor-agnostic solutions can be integrated into your environment.
What you do need to think through before deploying MFA is your own use case:
Check with your identity provider which MFA options it supports and which of them meet your requirements. Where possible, start with phishing-resistant methods for administrators and other high-value accounts.
Two-factor authentication (2FA) is MFA with exactly two factors. MFA covers two or more. In practice the terms are often used interchangeably.
It is better than a password alone, but it is the weakest MFA option. CISA describes SMS and voice codes as a last resort, and NIST SP 800-63B-4 classifies authentication via the phone network as restricted.
The authenticator cryptographically binds the sign-in to the genuine website or service, so a code or approval cannot be replayed through a fake page. FIDO2/WebAuthn, including passkeys, and PKI-based smart cards work this way.
A passkey combines possession of the device holding the private key with a local unlock by biometrics or PIN, so it covers two factors in one step. NIST SP 800-63B-4 accepts synced passkeys at AAL2.
Demystifying Security, the 2020 series: Mobile Threat Defense (MTD) | Multi-Factor Authentication (MFA) | Identity and Access Management (IAM) | Virtual Private Network (VPN) | Cloud Access Security Broker (CASB) | Zero Trust
Planning an MFA rollout or a move to passkeys on managed devices? Our team supports endpoint security and endpoint management projects, and our trainings prepare your administrators. Contact us with any questions.