StructureClerk

Multi-factor authentication

Also known as: MFA · 2FA · two-factor authentication

Multi-factor authentication requires at least two proofs of identity of different kinds to open a session: something you know, something you have, or something you are.

Its value rests entirely on the factors being different in kind. Two passwords are not two-factor authentication, because one database theft compromises both.

Not all factors are equal. A hardware key or an authenticator app resists phishing; a code by text message does not — it can be intercepted, and the number hijacked.

It has the best effort-to-effect ratio in all of security: it neutralises nearly every attack based on a stolen or reused password.

What it means for a small business

No infrastructure project required: it is a checkbox in the admin console of your email and cloud tools, and it covers the majority of real risk.

So what actually applies to you?

A definition tells you what a term means, not what your organization must do. The assessment answers the second question — free, no credit card.

Updated September 1, 2026 · Educational definition; not legal advice.