Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) is a security method in which users must confirm their identity through several independent factors. Even if a password or other credentials have been compromised, access remains blocked without the additional factor.

The factors come from different categories: knowledge (password, PIN), possession (smartphone, hardware token) and inherence (biometric features). Two-factor authentication (2FA) is the most common special case, with exactly two factors from different categories. Not all methods are equally strong: one-time codes via SMS or app can be bypassed through phishing and real-time relaying, whereas FIDO2-based methods such as passkeys or hardware keys are considered phishing-resistant.

MFA is considered one of the most effective individual measures against account takeovers and a basic building block of Identity Security. In combination with context-based policies, it contributes significantly to the implementation of Zero Trust.