Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA)
Authenticator 482 verify FACTOR 1 Password ●●●●●●●● FACTOR 2 Authenticator App ✓ ACCESS GRANTED ✓

Learn what MFA is, why it is essential, and how to set it up on your work accounts.

Multi-Factor Authentication (MFA)

Multi-Factor Authentication adds a second verification step beyond your password. Even if an attacker steals your password, they cannot log in without the second factor.

The Three Factors of Authentication

Authentication methods fall into three categories. True MFA uses at least two different categories:
Factor Type Examples
Something you know Knowledge Password, PIN, security question
Something you have Possession Authenticator app, hardware key, SMS code
Something you are Inherence Fingerprint, face recognition, retina scan

MFA Methods — From Weakest to Strongest

Not all MFA is equal. SMS codes are the weakest (vulnerable to SIM-swap and interception), authenticator apps and push notifications are stronger, and phishing-resistant options like FIDO2 passkeys and hardware keys (e.g. YubiKey) are the strongest.

MFA Fatigue Attacks

Attackers who have stolen your password can trigger repeated MFA push notifications, hoping you will eventually tap “Approve” to make them stop. This is called an MFA fatigue attack.
⚠ Important
If you receive unexpected MFA requests you did not initiate — especially multiple in a row — do not approve them. This means someone has your password. Deny all requests, change your password immediately, and report it to IT.

Enabling MFA — Where to Start

Prioritise MFA on your highest-value accounts:
  1. Work email and Microsoft 365 / Google Workspace
  2. Banking and financial accounts
  3. Password manager
  4. Any account that has access to sensitive data
✓ Key Point
Even SMS-based MFA is vastly better than no MFA. Enabling any form of MFA blocks the majority of automated credential-stuffing attacks instantly. Don’t wait for the perfect option — enable it today on your most important accounts.