Skip to content
DopeSwagYolo

AI & Cybersecurity

What is multi-factor authentication (MFA)?

Multi-factor authentication (MFA) is a sign-in method that requires two or more different kinds of proof of identity. An example is a password plus a code from a phone or a fingerprint. So a stolen password alone is not enough.

Also known as: MFA, 2FA, two-step verification

Researched and fact-checked by AI, with no human review. 7 sources listed below. How we verify

Last updated

How it works

The US National Institute of Standards and Technology (NIST) glossary defines MFA as an authentication system that requires more than one distinct type of factor. The three types are:

  • something you know, like a password
  • something you have, like a hardware token
  • something you are, like a fingerprint

NIST's digital identity guideline SP 800-63B-4, published in July 2025, sets three authentication assurance levels (AALs). AAL1 permits a single factor. AAL2 requires proof of two distinct factors, and services must offer at least one phishing-resistant option. AAL3 requires a phishing-resistant authenticator whose private key cannot be exported.

Why it matters

With MFA enabled, an attacker who steals a password still needs the second factor, a fact sheet from the US Cybersecurity and Infrastructure Security Agency (CISA) explains. Microsoft's documentation, citing company research, says MFA can block more than 99.2% of account compromise attacks.

The CISA fact sheet, dated October 2022, ranks codes sent by text message or voice call as the weakest form. They are exposed to phishing, SIM swapping and flaws in the SS7 phone signaling protocol. In SIM swapping, a criminal gets a carrier to move the victim's number to another SIM. App approvals without number matching are open to push bombing, repeated prompts sent until the user accepts. CISA calls phishing-resistant MFA, built on FIDO/WebAuthn or on public key infrastructure such as smart cards, the gold standard.

A joint advisory from the FBI, CISA and agencies in Canada, Australia and the UK was last revised July 29, 2025. It says the Scattered Spider cybercriminal group has used push bombing and SIM swaps. It says the group has posed as employees to get IT help desks to move a worker's MFA to devices it controls.

Where things stand in 2026

Microsoft's documentation says it began requiring MFA for Azure portal sign-ins in October 2024 and for command-line and other management tools from October 1, 2025. Customers could postpone that second phase until July 1, 2026.

On April 23, 2026, the UK National Cyber Security Centre said all traditional MFA methods, including SMS codes, app-generated one-time passwords and push approvals, are inherently phishable. It said it would begin recommending passkeys where services support them and two-step verification elsewhere. Under the NIST guideline, US federal agencies must require staff, contractors and partners to use phishing-resistant authentication to access federal information systems.

Sources

  1. multi-factor authentication - Glossary | CSRC, NIST Computer Security Resource Center
  2. SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management, NIST Computer Security Resource Center
  3. Authentication Assurance Levels, National Institute of Standards and Technology (NIST), SP 800-63B-4 online edition
  4. Implementing Phishing-Resistant MFA (fact sheet, October 2022), Cybersecurity and Infrastructure Security Agency (CISA)
  5. Scattered Spider (Cybersecurity Advisory AA23-320A), Cybersecurity and Infrastructure Security Agency (CISA)
  6. Plan for mandatory Microsoft Entra multifactor authentication (MFA), Microsoft Learn
  7. Passkeys are more secure than traditional ways to log in, UK National Cyber Security Centre (NCSC)

Articles on AI & Cybersecurity