IT security

Multi-Factor Authentication

Also known as: MFA · Two-Factor Authentication · 2FA

In short

Multi-factor authentication requires at least two independent proofs of identity at login instead of a password alone.

Multi-factor authentication (MFA) requires at least two of three possible proofs at login: something you know, such as a password; something you have, such as a phone or a security key; and something you are, such as a fingerprint. The point is that a stolen or guessed password alone is no longer enough to gain access. When exactly two factors are used, it's also called two-factor authentication, or 2FA.

In practice, a user enters a code generated by an app on their phone after the password, or confirms the login with a tap on the same device. Physical security keys, confirmed over USB or wirelessly, are also common. Without that second step, nobody gets past login, even with the correct password.

A common mistake is setting up MFA for only a single service, such as email, while VPN or cloud access still works with a password alone – exactly where a stolen password can do the most damage. It's also risky to send the second factor by SMS, since SMS codes can be intercepted more easily than app-based or physical methods.

What it means in practice

In many SMEs, MFA is set up on one system at best, while VPN access, the email inbox and cloud storage remain reachable with a single password. One sign of this is a stolen password working for login with no further step required. NDVDL sets up multi-factor authentication for a business's key access points, in particular VPN, email and cloud services.

Is this handled properly at your site?

We look at how it actually stands with you — and say honestly whether anything needs doing.

IT security & firewall

A term from your quote missing here?

Send us the passage you do not follow. We will explain it — with no obligation to order anything.