NMS - New Media Service GmbH
Hands on a laptop keyboard, a keyring and a smartphone beside them
AI-generated

MFA – Multi-Factor Authentication

MFA explained: Why a second factor should be standard, which methods are secure, and where the limits lie.

IT Glossary

In brief

Multi-Factor Authentication (MFA) requires a second proof of identity in addition to a password, such as a confirmation in an app, a security key, or a biometric feature. As a result, a stolen password alone is no longer sufficient for access.

Not all methods are equally secure. SMS codes can be intercepted, and simple push notifications can be forced through repeated requests. More secure options include number-matching confirmations, device-bound authenticator apps, and phishing-resistant methods such as security keys or passkeys.

MFA is effectively mandatory in many regulatory frameworks and is explicitly part of the catalogue of measures under NIS2. In Microsoft environments, it is configured together with Conditional Access so that access is evaluated on a risk basis. See IT Security.