Multi-Factor Authentication (MFA)
An authentication method that requires two or more independent factors from different categories, such as a password plus a hardware key or a biometric, so that one stolen factor is not enough to gain access.
Authentication factors fall into three categories: something the user knows, such as a password or PIN; something the user has, such as a phone, smart card or security key; and something the user is, such as a fingerprint or face. MFA combines factors from at least two categories. Common methods include one-time codes from authenticator apps based on the TOTP standard, push notifications, SMS codes, smart cards and FIDO2 security keys or passkeys.
MFA is one of the most effective controls against account takeover through phishing, password reuse and credential stuffing, and many frameworks require or recommend it; PCI DSS, for example, requires MFA for all access into the cardholder data environment. Priority uses include remote access, email, cloud administration, privileged accounts and remote connections into industrial networks.
Not all MFA offers equal protection. SMS codes are vulnerable to SIM swapping and interception, and one-time codes and push approvals can be phished or abused through repeated prompts, a technique known as MFA fatigue. Phishing-resistant methods based on public-key cryptography, such as FIDO2 and WebAuthn, bind authentication to the genuine website. NIST SP 800-63B defines authenticator assurance levels that reflect these differences.
Key points
- Combines factors from at least two categories: knowledge, possession and inherence.
- Stops attacks that rely on a stolen password alone.
- SMS and push methods are weaker than phishing-resistant FIDO2 methods.
- PCI DSS requires MFA for all access into the cardholder data environment.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- PasskeysCybersecurity & Compliance
- PhishingCybersecurity & Compliance
- Password HashingCybersecurity & Compliance
- Zero Trust Architecture (ZTA)Cybersecurity & Compliance
- Principle of Least PrivilegeCybersecurity & Compliance
- Payment Card Industry Data Security Standard (PCI DSS)Cybersecurity & Compliance