Multi-Factor Authentication
Multi-Factor Authentication (MFA) is a security method that requires a user to provide two or more different pieces of evidence to prove their identity before gaining access to a system, application, or data. Instead of relying on a password alone, it adds one or more additional verification steps. This layered approach makes it harder for an unauthorized person to access an account even if one factor, such as a password, is compromised.
MFA is an authentication system that requires the successful presentation of more than one distinct authentication factor to grant access to a resource. It applies a layered approach in which a user must combine two or more independent factors, and it is sometimes referred to as two-step verification or, in its two-factor form, 2FA. MFA is a technical security control rather than a legal obligation in itself, though its use may be required or recommended under specific regulatory or contractual regimes depending on jurisdiction, sector, and risk level; readers should verify applicable requirements against the relevant authoritative source. The evidence provided does not enumerate the specific categories of authentication factors, so implementation details should be confirmed against current official guidance.
Why it matters
Passwords alone are a single point of failure. If a password is guessed, phished, reused across services, or exposed in a breach, an attacker who obtains it can generally gain access to the associated account. Multi-Factor Authentication (MFA) addresses this weakness by requiring a user to present a combination of two or more distinct verification factors, so that a compromised password on its own is typically insufficient to grant access. This layered approach materially raises the effort required for unauthorized access.
For compliance and security teams, MFA is one of the most commonly cited access controls in security guidance. It is worth stressing that MFA is a technical security control, not a legal obligation in itself. Its use may be required or recommended under specific regulatory or contractual regimes, but whether it is mandatory in a given case depends on jurisdiction, sector, and risk level. Organizations should verify applicable requirements against the relevant authoritative source rather than assuming MFA is universally mandated or, conversely, always optional.
Because the strength of an MFA deployment depends on implementation choices, MFA should be understood as a risk-reduction measure rather than a guarantee. The evidence here describes MFA at a conceptual level and does not enumerate the specific categories of authentication factors or their relative resilience; implementation details and their suitability for a particular threat model should be confirmed against current official guidance and professional judgment.
Who it's relevant to
Inside MFA
Common questions
Answers to the questions practitioners most commonly ask about MFA.
