ISEC7 Digital Workplace Blog

What Is MFA? Multi-Factor Authentication Explained

Written by Remi Keusseyan | Aug 25, 2020, 7:30:00 AM

Reviewed and updated in October 2026.

Passwords alone no longer protect an account. Multi-Factor Authentication adds a second line of defense that most organizations can switch on quickly. Here is what it is, how it works, and which variants actually stop today's phishing attacks.

Multi-Factor Authentication (MFA) is a sign-in method that requires two or more independent pieces of evidence, called factors, before access is granted: something you know, something you have, or something you are. A stolen password alone is then not enough to take over an account. Phishing-resistant MFA, such as FIDO2 security keys, passkeys or smart cards, goes further and cannot be relayed through a fake login page.

What are the factors?

  • Knowledge: something only the user knows, such as a password or PIN
  • Possession: something only the user has, such as a mobile device, a hardware token or a smart card
  • Inherence: something only the user is, such as a fingerprint, face or voice

What does MFA do?

MFA strengthens authentication by adding another layer of security. It does not rely on credentials alone, since these may be compromised, but also asks for complementary evidence that only the user can provide at that moment.

There are several variants depending on the number and type of factors (two-factor authentication or 2FA, two-step verification and so on), but they all rest on the same basic concept.

Why do you need MFA?

Applied to mobility, MFA verifies that whoever tries to access a corporate resource, on-premises or in the cloud, is in fact who they claim to be, by asking for a second (and possibly third) factor after the initial authentication.

MFA is part of daily life. At an ATM, the user needs the card (physical, or virtual on a phone or watch) and must know the PIN to complete the transaction. If you have ever used a token to establish a VPN connection to your company network, you have already used MFA.

Things have evolved since then. With mobile devices at the center of everything, there are options that need no easy-to-lose piece of plastic. MFA providers know that a phone or wearable is rarely left at home, so they built several ways to make authentication easy:

  1. Receive a code via phone call or SMS on a previously registered, trusted device
  2. Generate a one-time password (OTP) in an authenticator app on a trusted mobile device
  3. Approve the sign-in in an app on a trusted mobile device (push notification)
  4. Sign in with a passkey or FIDO2 security key, unlocked by fingerprint, face or PIN

Many people know these methods from setting up accounts with Microsoft, Google or Apple. The same methods are available for companies to implement.

Not all MFA is equal: phishing-resistant MFA

Since this article first appeared, attackers have learned to defeat the weaker methods. Fake login pages relay codes in real time, SIM swaps redirect SMS, and repeated push prompts wear users down until they approve one ("MFA fatigue"). In its fact sheet Implementing Phishing-Resistant MFA (October 2022), CISA therefore ranks the methods:

  • Phishing-resistant: FIDO2/WebAuthn authenticators and PKI-based methods such as smart cards. CISA calls FIDO/WebAuthn the only widely available phishing-resistant authentication.
  • Interim: push notifications with number matching, where the user types a number shown on the login screen into the app
  • Last resort: codes via SMS or voice call, which are vulnerable to phishing, SS7 and SIM swap attacks

NIST points the same way. SP 800-63B-4, finalized in July 2025, requires verifiers at authentication assurance level 2 (AAL2) to offer at least one phishing-resistant option and requires phishing resistance at AAL3. Out-of-band codes via the phone network are a "restricted" authenticator. Synced passkeys are accepted at AAL2, but not at AAL3. How passkeys work in practice is explained in Goodbye Passwords, Hello Passkeys, and how attackers target identities in How to Thwart Phishing Attacks with Enhanced Identity Management.

Which MFA should you choose?

You may not have to choose at all: most identity providers (IdPs), such as Microsoft Entra ID or Google Workspace, already include MFA. If not, vendor-agnostic solutions can be integrated into your environment.

What you do need to think through before deploying MFA is your own use case:

  • Which resources do users access most, and where are they located (on-premises, cloud or both)?
  • Which devices do users rely on most: operating system (iOS, Android, Windows, macOS), type (smartphone, tablet, desktop), personally or corporate owned, and for corporate devices, are they managed?
  • Which factors do you want to use: passkeys or security keys, smart cards, push approval with number matching, OTP from an authenticator app, or codes via SMS or phone call as a fallback?
  • If you use an authenticator, which type: a desktop or mobile app, or a physical security key?

Check with your identity provider which MFA options it supports and which of them meet your requirements. Where possible, start with phishing-resistant methods for administrators and other high-value accounts.

Frequently asked questions

What is the difference between MFA and 2FA?

Two-factor authentication (2FA) is MFA with exactly two factors. MFA covers two or more. In practice the terms are often used interchangeably.

Is SMS-based MFA still acceptable?

It is better than a password alone, but it is the weakest MFA option. CISA describes SMS and voice codes as a last resort, and NIST SP 800-63B-4 classifies authentication via the phone network as restricted.

What makes MFA phishing-resistant?

The authenticator cryptographically binds the sign-in to the genuine website or service, so a code or approval cannot be replayed through a fake page. FIDO2/WebAuthn, including passkeys, and PKI-based smart cards work this way.

Are passkeys a form of MFA?

A passkey combines possession of the device holding the private key with a local unlock by biometrics or PIN, so it covers two factors in one step. NIST SP 800-63B-4 accepts synced passkeys at AAL2.

Demystifying Security, the 2020 series: Mobile Threat Defense (MTD) | Multi-Factor Authentication (MFA) | Identity and Access Management (IAM) | Virtual Private Network (VPN) | Cloud Access Security Broker (CASB) | Zero Trust

Planning an MFA rollout or a move to passkeys on managed devices? Our team supports endpoint security and endpoint management projects, and our trainings prepare your administrators. Contact us with any questions.