Skip to main content

Multi-Factor Authentication (MFA)

MFApractice

Multi-Factor Authentication requires a user to present evidence from at least two distinct authentication-factor categories before access is granted.

Status: published
Last reviewed: 2026-09-12

Technical explanation

Factors commonly include something known, possessed, or inherent to the claimant. Strong MFA combines independent factors and resists phishing through cryptographic authenticators such as passkeys or security keys. Two steps using the same factor category do not necessarily constitute MFA.

Business relevance

MFA reduces account takeover from stolen or reused passwords and is a foundational control for remote access, administration, and sensitive applications.

Implementation example

Administrators authenticate with a password and a phishing-resistant hardware key, while recovery requires separately controlled identity verification and is fully logged.

Limitations and common misconceptions

MFA is not immune to phishing, session theft, insecure recovery, push fatigue, or compromised endpoints. SMS and one-time codes generally provide weaker protection than phishing-resistant authenticators.

Discuss your systems

Need help implementing or evaluating this concept? Keenfunnel designs connected AI, automation, and data systems.

Book a discovery session