MFA definition
Multi-factor authentication (MFA) is a security method that requires users to prove their identity with two or more independent factors before gaining access: something they know, such as a password; something they have, such as a phone or security key; or something they are, such as a fingerprint. It blocks most attacks using stolen passwords.
How does multi-factor authentication work?
After entering a password, the user must complete another check from a different category, such as approving a push notification, entering a code from an authenticator app or touching a hardware security key. Even if an attacker steals or guesses the password through phishing, a data breach or credential stuffing, they cannot log in without the second factor. Adaptive MFA adjusts requirements based on risk, asking for extra verification for new devices, unusual locations or sensitive actions.
Types of authentication factors and methods
MFA methods differ significantly in security and convenience, and attackers have adapted to weaker ones. Choosing the right methods for each group of users, such as stronger factors for administrators and finance staff, matters as much as enabling MFA at all. The common methods, roughly from weakest to strongest, are listed below.
- SMS or voice codes: better than passwords alone, but vulnerable to SIM swapping and interception.
- Email codes: convenient but only as secure as the email account.
- Authenticator app codes (TOTP): apps like Google Authenticator or Microsoft Authenticator.
- Push notifications with number matching to resist approval fatigue.
- Hardware security keys using FIDO2, such as YubiKey.
- Passkeys: FIDO2 credentials stored on devices and confirmed with biometrics.
What is phishing-resistant MFA?
Attackers now use phishing kits that proxy login pages in real time, capturing both the password and the one-time code as the victim enters them, or flood users with push requests until one is approved. Phishing-resistant methods, based on FIDO2 and WebAuthn standards, such as security keys and passkeys, cryptographically bind authentication to the genuine website domain, so they simply do not work on a fake site. Security agencies increasingly recommend these methods, especially for administrators and high-value accounts.
How to roll out MFA
Start with the accounts that matter most: email, identity provider, cloud consoles, source code repositories, VPN or remote access and finance systems. Centralize authentication through a single identity provider with single sign-on, so MFA is enforced consistently. Offer convenient methods, such as passkeys and push with number matching, provide backup codes and a secure recovery process, and remove legacy protocols that bypass MFA. Service accounts need separate controls such as short-lived credentials.
Communicate before enforcing, give users time to enroll, and monitor for accounts still without MFA. Help desk recovery procedures need strong identity verification, because attackers often target support staff to reset a victim's MFA. Track enrollment rates by department and follow up personally with teams that lag behind.
MFA in your own applications
Customer-facing applications benefit from MFA too, particularly for financial, health and admin functions. Identity platforms such as Auth0, Amazon Cognito, Firebase Authentication and Microsoft Entra External ID provide MFA and passkeys without building cryptography yourself. Nexzem implements MFA and passkey login in client applications, balancing security with sign-in friction for each type of user. Step-up prompts for risky actions keep everyday sign-in simple.