Cybersecurity · Foundations
Multi-Factor Authentication (MFA)
On this page 9 sections
In 30 seconds
MFA stands for multi-factor authentication: signing in with two or more different kinds of proof. The proof categories are the three factors — something you know, such as a password; something you have, such as a phone or security key A small hardware device that connects to a computer and cryptographically proves that you possess it. Full entry →; and something you are, such as a fingerprint. Requiring two different kinds means a stolen password alone is no longer enough to get in, and that is the whole point of MFA.
Why this matters
Passwords leak. They are guessed, reused, and stolen in breaches, and when a password alone guards an account, whoever holds it walks in as you. MFA closes that gap by adding a second kind of proof an attacker probably lacks: a code delivered to your phone, a physical key, or your face. CISA reports that users who enable MFA are up to 99 percent less likely to have an account compromised. Understanding MFA matters because it is the single most effective step most people can take, because not all MFA methods are equal, and because attackers now target the weaknesses of MFA itself. Knowing how it works lets you choose stronger options and recognize when a prompt you did not expect is a warning sign rather than a routine check.
The college version
What multi-factor authentication is
multi-factor authentication (MFA) A sign-in process that requires two or more distinct kinds of authentication factor before granting access. Full entry → is a sign-in process that demands proof from two or more different categories before entry. NIST, whose Special Publication 800-63B sets U.S. digital-authentication practice, defines MFA as an authentication system requiring more than one distinct type of authentication factor One of the three kinds of proof: something you know, something you have, or something you are. Full entry → for successful authentication. The categories are the three factors from the authentication lesson: something you know, a secret such as a password; something you have, a device such as a phone or security key; and something you are, a physical trait such as a fingerprint or a face. The word distinct does the work here. A password and a PIN both fall under “something you know,” so the two together still count as a single factor. MFA means two or more different kinds, such as a password plus a phone-delivered code, or a hardware key plus your fingerprint. The authentication lesson covers the factors in detail; this lesson is about the combination and why it matters.
Why MFA helps: a stolen password is not enough
A password is a single point of failure. Breaches leak password databases, people reuse the same password across many sites, and lookalike pages trick users into typing it in. When a password alone protects an account, anyone who obtains it can sign in as the owner. MFA changes the math: the attacker would also need the second, different kind of proof. CISA, the U.S. agency responsible for cybersecurity, reports based on industry research that users who enable MFA are up to 99 percent less likely to have an account compromised. A concrete case makes the benefit plain. Priya's email password is stolen when a retailer she shops at is breached, and she had reused that password for her email. With password-only sign-in, the thief can read her mail within minutes. With MFA enabled, the sign-in also demands a code generated on her phone, and the thief does not have her phone, so the attempt fails. The password was compromised, but the account was not. That separation, between a stolen credential and a usable sign-in, is the core benefit of MFA.
Common MFA methods
The common methods are instances of the three factors. One-time codes: a short number delivered by text message or generated by an authenticator app, entered after the password. Push approvals: a prompt sent to an app on your phone asking you to approve or deny a sign-in attempt. Security keys: compact hardware that plugs into a computer and proves possession cryptographically; Microsoft documents FIDO2 security keys and passkeys among its supported authentication methods. Biometrics: your fingerprint or face, checked on a device you control. Each method adds a second kind of proof, which is what makes the combination multi-factor. But the methods are not equally strong, which is the next point.
The limits: SMS is weaker, and nothing is perfect
A general hierarchy runs through guidance from NIST, CISA, and Microsoft: security keys are the strongest common method, authenticator apps are strong, and SMS text codes are the weakest of the common methods. NIST classifies the use of the public telephone network, which carries SMS and voice codes, as a restricted authenticator An authentication method that NIST allows only with explicit risk acceptance; the public telephone network currently holds this status. Full entry →: an organization that accepts it must assess, understand, and accept risks that will likely increase over time. CISA's advisory guidance states that physical security tokens are the most secure form of MFA, followed by authenticator applications. Microsoft likewise recommends phishing-resistant methods such as security keys over SMS-based sign-in. The practical reason is that SMS codes travel over phone networks that can be intercepted or redirected, while a code generated on a device you hold, or a cryptographic key you own, is far harder to capture. Even so, SMS-based MFA is still far better than no MFA at all: the hierarchy is about choosing the strongest option available, not dismissing a weaker one. And no method is perfect. Phones get lost, authenticator apps can be moved to a new device, biometrics are not secrets and cannot be reset like passwords, and even a security key can be stolen along with the device it unlocks.
Attacks on MFA, and the guidance
Because MFA is strong, attackers try to defeat it rather than ignore it. The best-known approach is MFA fatigue An attack in which a person is sent repeated authentication prompts in the hope that they approve one. Full entry →, which NIST defines in its threat discussion as an attacker causing repeated authentication requests to be sent to a subscriber in an effort to get them to approve; a tired or distracted user may approve a fraudulent request just to stop the notifications. Other attacks aim at the weaker methods: tricking users into revealing codes through lookalike pages is covered in the phishing lesson, and redirecting a phone number is part of why text codes are the weaker option. The defensive guidance is straightforward and general. Enable MFA on your important accounts wherever it is offered. Where you have a choice, prefer an authenticator app or a security key over text codes. Treat unexpected authentication prompts as suspicious: if you were not signing in, a request to approve a sign-in is a warning sign, not a routine check. No single method is bulletproof, but MFA makes ordinary account compromise dramatically harder, and that is the point.

Eli explains
The same idea, in plain words
Explain it like I’m 10
MFA means proving you are you in two different ways before a computer lets you in. Think of the three ways: something you know, like a password in your head; something you have, like your phone or a small key that plugs into a computer; something you are, like your fingerprint or your face. One way alone can be stolen: a password can leak, a phone can be borrowed. Two different ways are much harder to fake at once, because a thief who stole your password probably does not also have your phone. That is why important accounts ask for a code from your phone after you type your password.
Picture it like this
Imagine a club with two doors. The first door opens with a word you memorized. The second door opens only with a special coin that lives in your pocket. A thief who overhears the word gets through the first door and then stands at the second one, empty-handed, because the coin never left your pocket. That second door is MFA: it makes knowing the secret not enough. A club with only the word door lets anyone who heard the word walk all the way in.
Where the picture stops working
The comparison has limits. Real MFA doors are not always locked the same way: text-message codes travel over phone networks that can be intercepted, so that second door is weaker than a security key, which is closer to the unstealable coin. And attackers do not always try to pick the doors; sometimes they bombard the person inside with requests to open the second door until, tired, they open it themselves. That is MFA fatigue, and no lock design fully removes the human at the door.
Worked example
Marco's bank account is protected by MFA. One evening he receives an email from a delivery service asking him to confirm a package by signing in, and he types his bank password into the page without noticing the address is wrong. The page is fake, and the thief now has his password. But the bank's sign-in also requires a six-digit code from Marco's banking app, which the thief cannot produce. When the thief tries to sign in, the bank asks for the code, the attempt fails, and the bank's systems flag the login from an unfamiliar device. Marco's password was stolen, yet the account stayed locked. The second factor, the app on his phone, was the difference between a stolen password and a stolen account.
Key takeaway
MFA requires two or more different kinds of proof, so a stolen password alone is no longer enough to get in. Enable MFA on important accounts, and prefer authenticator apps or security keys over text codes; no method is perfect, but MFA makes compromise dramatically harder.
Quick check
3 questions here, of 5 in this lesson’s practice set. Answers stay hidden until you check.
A login asks for a password and then a six-digit code from an authenticator app. Which factor categories are in use?
Dana's password was stolen in a breach, yet her account stayed safe. Which explanation best fits?
Study tools & related lessonsYou’ll learn to · Common mistakes · Easily confused · Key vocabulary · Related
You’ll learn to
- Define multi-factor authentication as a sign-in requiring two or more distinct kinds of proof.
- Name the three authentication factors and identify which factor each common MFA method uses.
- Explain why MFA protects an account even when its password has been stolen.
- Compare the relative strength of common MFA methods, including why SMS codes are weaker than app codes or security keys.
- Describe MFA fatigue and other attacks on MFA at a conceptual level.
- Apply MFA best practices to everyday account choices.
Common mistakes
Assuming a password plus a PIN is multi-factor authentication.
Both are something you know, so together they count as one factor. MFA needs two or more different kinds of proof, like a password plus a code from your phone.
Believing all MFA methods are equally strong.
Security keys are generally the strongest common method, authenticator apps next, and SMS text codes the weakest, per CISA and NIST. Even so, SMS-based MFA beats no MFA.
Treating any unexpected authentication prompt as routine.
MFA fatigue works by flooding users with approval requests until one gets accepted. If you are not signing in, a sign-in prompt you did not ask for is a warning sign.
Thinking MFA makes an account unbreakable.
No method is perfect. MFA raises the bar dramatically, but phones get lost, codes can be intercepted, and users can be tricked or pressured. It is a strong layer, not a magic shield.
Easily confused
SMS text codes vs. Authenticator app codes
Both are one-time codes, but SMS travels over the phone network, which NIST treats as a restricted authenticator with risks that increase over time; app codes stay on a device you control, so they are generally the stronger option.
Security keys vs. Push approvals
A security key proves possession cryptographically and resists remote capture; a push approval is convenient but depends on the user correctly recognizing a request, which is exactly what MFA fatigue exploits.
Single-factor sign-in vs. Multi-factor sign-in
Single-factor asks for one kind of proof, typically a password; MFA asks for two or more distinct kinds, so a stolen password alone is no longer enough to get in.
Key vocabulary
- multi-factor authentication (MFA)
- A sign-in process that requires two or more distinct kinds of authentication factor before granting access.
- factor
- One of the three kinds of proof: something you know, something you have, or something you are.
- one-time code
- A short, single-use number sent by text message or generated by an app, used as something-you-have proof.
- push approval
- A notification sent to an app asking the account holder to approve or deny a sign-in attempt.
- security key
- A small hardware device that connects to a computer and cryptographically proves that you possess it.
- biometric
- A physical trait like a fingerprint or face, used as proof of identity.
- MFA fatigue
- An attack in which a person is sent repeated authentication prompts in the hope that they approve one.
- restricted authenticator
- An authentication method that NIST allows only with explicit risk acceptance; the public telephone network currently holds this status.
Sources & references
- NIST Special Publication 800-63B: Authentication and Authenticator Management — National Institute of Standards and Technology
- Cybersecurity Advisory AA22-074A: Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and 'PrintNightmare' Vulnerability — U.S. Cybersecurity and Infrastructure Security Agency (CISA)
- Microsoft Entra authentication overview — Microsoft Learn (Microsoft Entra ID)
EliExplains lessons are original prose written from the open, credible references above. See Copyright & Licensing.
Researched 2026-08-21
Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.

