Multi-factor authentication
Also known as: MFA · 2FA · two-factor authentication
Multi-factor authentication requires at least two proofs of identity of different kinds to open a session: something you know, something you have, or something you are.
Its value rests entirely on the factors being different in kind. Two passwords are not two-factor authentication, because one database theft compromises both.
Not all factors are equal. A hardware key or an authenticator app resists phishing; a code by text message does not — it can be intercepted, and the number hijacked.
It has the best effort-to-effect ratio in all of security: it neutralises nearly every attack based on a stolen or reused password.
What it means for a small business
No infrastructure project required: it is a checkbox in the admin console of your email and cloud tools, and it covers the majority of real risk.
Related terms
So what actually applies to you?
A definition tells you what a term means, not what your organization must do. The assessment answers the second question — free, no credit card.
Updated September 1, 2026 · Educational definition; not legal advice.