Multi-Factor Authentication: What It Does and Why It Helps

Article 8 min Beginner
Learn how multi factor authentication protects accounts, how authentication factors work, why some methods resist phishing better and how to protect recovery.
Suitable for
All Ages

A password is often the first thing protecting an online account.

Multi factor authentication adds another form of verification so that knowing the password alone may not be enough to sign in.

This extra protection is useful because passwords can be stolen through phishing, data breaches, malware, password reuse or other attacks.

Multi factor authentication does not make an account impossible to compromise, but it can make unauthorized access much harder.

What is multi factor authentication?

Authentication is the process of proving that you are allowed to access an account or service.

Multi factor authentication requires evidence from more than one type of authentication factor.

Common factor types are:

  • something you know
  • something you have
  • something you are

A password is something you know.

A trusted security key or device can be something you have.

A biometric characteristic used with a trusted device can contribute something you are.

Why the word factor matters

Two passwords do not create two factor authentication.

A password and a security question are also both examples of something you know.

Using two pieces of information from the same factor category is still relying on the same general type of proof.

True multi factor authentication combines different factor types.

A simple example

Imagine an account that asks for:

  1. your password
  2. approval from a trusted authentication device

The password is something you know.

The trusted device provides something you have.

An attacker who steals only the password may still be unable to complete the second requirement.

Why passwords alone can fail

A password can be strong and still be stolen.

For example, an attacker may:

  • trick you into entering it on a fake website
  • steal it from a compromised service
  • capture it using malicious software
  • obtain it from another account where you reused the same password

Multi factor authentication gives the account another check beyond the password.

Where should you enable it first?

Start with accounts whose compromise could cause the most damage.

Important examples include:

  • your primary email account
  • password manager account
  • banking and financial accounts
  • cloud storage
  • important work accounts
  • social accounts
  • shopping accounts containing payment information

Email deserves special attention because many other services use email for password resets and account recovery.

Common types of additional authentication

Online services support different authentication methods.

These can include:

  • codes created by an authenticator application
  • codes sent to a registered phone number
  • approval requests sent to a trusted device
  • physical security keys
  • cryptographic credentials stored on a device
  • passkeys

The exact options depend on the service.

Not every MFA method provides the same protection

Using an additional factor is generally safer than relying only on a password, but different methods resist attacks differently.

Some methods can still be tricked by phishing.

For example, a criminal operating a fake login page may ask you to enter both your password and a temporary verification code.

If you provide both, the attacker may try to use them immediately on the real service.

Temporary codes are useful but not fully phishing resistant

Authenticator applications can generate temporary codes that change regularly.

These codes strengthen an account because an attacker normally needs more than the password.

However, manually entered codes can still be captured by a convincing phishing site.

Never give a verification code to someone who contacts you unexpectedly.

Text message codes

Some services send verification codes by text message.

This is still an additional protection compared with using only a password.

However, text based authentication can have weaknesses involving phone account takeover, message interception and phishing.

If a service offers a stronger practical option, consider using it.

Push approval requests

Some authentication applications send a sign in approval request to your phone.

This can be convenient, but you should never approve a request you did not initiate.

An attacker who already knows your password may repeatedly send approval requests hoping that you will eventually accept one.

This is sometimes called authentication fatigue.

Never approve an unexpected request

If an authentication request appears when you are not signing in:

  1. deny the request
  2. do not approve it simply to make the notification disappear
  3. check the account for suspicious activity
  4. change the password if there is evidence it may be compromised
  5. follow the provider's official security instructions

An unexpected request can be evidence that someone already knows part of your login information.

Number matching can reduce accidental approval

Some services show a number on the login screen and require you to select or enter the matching number on your trusted device.

This creates more interaction than a simple approve button.

It can reduce the chance of approving an unrelated request without thinking.

You should still verify that you actually started the login attempt.

What is phishing resistant authentication?

Phishing resistant authentication uses a design that does not depend only on the user recognizing a fake website.

The authentication process is cryptographically connected to the real service.

This makes it much harder for a fake site to capture something and reuse it to impersonate you.

Security keys and properly implemented FIDO based authentication are common examples.

Passkeys can provide strong authentication

Passkeys use cryptographic credentials rather than asking you to type a traditional password into every service.

A passkey is associated with the service for which it was created.

You commonly unlock its use through the security of your device, such as a device passcode or biometric check.

This design can provide strong protection against ordinary credential phishing.

A biometric is not simply a replacement password sent to a website

When you use a fingerprint or face check with a modern authentication system, the biometric often unlocks a credential held by your device.

The service does not necessarily receive your fingerprint or face data as though it were a password.

The exact implementation depends on the device and service.

What happens when MFA is enabled?

A typical setup process may look like this:

  1. sign in to the real account
  2. open the security settings
  3. choose the authentication or verification option
  4. register the additional method
  5. complete a verification test
  6. save any recovery information safely

Always follow the service provider's official instructions.

Recovery is part of MFA security

Additional authentication creates an important question:

What happens if I lose the additional factor?

You might lose a phone, replace a device or misplace a security key.

Before depending on MFA, understand how the account can be recovered.

Recovery codes

Some services provide emergency recovery codes.

These codes may allow access when your normal additional authentication method is unavailable.

Because they can help bypass the normal second step, they are sensitive.

Store them according to the service provider's instructions and keep them away from people who should not have account access.

Do not make recovery weaker than the account

An account protected by strong authentication can still be vulnerable if its recovery process is easy for an attacker to abuse.

Review:

  • recovery email addresses
  • registered phone numbers
  • trusted devices
  • recovery codes
  • backup authentication methods

Remove outdated recovery information when the service allows it.

Have more than one safe way to recover important accounts

For an important account, losing one device should not permanently lock you out if the service provides safe backup options.

Depending on the service, you may be able to register another trusted authenticator, store recovery codes or use another approved recovery method.

Do not create insecure backup methods merely for convenience.

MFA does not replace a unique password

If an account still uses a password, that password should remain strong and unique.

Do not reuse a weak password simply because MFA is enabled.

A good security approach combines protections rather than allowing one protection to excuse another weakness.

MFA does not remove phishing risk completely

A criminal may still try to:

  • steal your password
  • steal a temporary code
  • trick you into approving a request
  • steal account recovery information
  • persuade support staff to change account access

The strongest practical authentication methods reduce some of these risks, but you should continue to recognize suspicious requests.

Never share a verification code because someone asks for it

A legitimate verification code is normally intended for the authentication process you initiated.

A person contacting you by telephone, message, email or social media may claim that they need the code to confirm your identity.

Do not provide it.

If you are concerned about the account, open the provider's official application or website independently.

Be careful with QR codes during setup

Some authenticator applications are registered by scanning a QR code displayed by the service.

That setup information can be sensitive because it may help create future authentication codes.

Only scan the setup code while using the real account service and do not share screenshots of it.

What if you replace your phone?

Do not wait until the old phone is erased to think about authentication.

Before changing devices:

  1. review which important accounts depend on the old device
  2. check each provider's official migration instructions
  3. confirm that recovery information is current
  4. register the new device when appropriate
  5. test access before removing the old method

The exact process differs between services.

What if your phone is lost?

If a phone containing authentication applications is lost, follow the relevant service and device provider instructions.

Actions may include:

  • remotely securing the device
  • removing the lost device from trusted device lists
  • using a recovery code
  • using another registered authenticator
  • reviewing recent account activity

Do not automatically turn off MFA permanently simply because a device was lost.

Protect the device that holds your authentication method

If your phone or computer is used as an authentication device, secure it with:

  • a device lock
  • current software updates
  • automatic locking
  • careful control of who can use the device

The security of the authentication method depends partly on the security of the device holding it.

Use stronger methods when the service supports them

If an important service offers several authentication methods, consider their security as well as convenience.

Phishing resistant methods such as properly implemented FIDO credentials can provide stronger protection than manually entered temporary codes.

Use the strongest practical method that you can maintain safely and recover correctly.

Common MFA mistakes

  • approving a sign in request you did not start
  • sharing temporary codes with another person
  • scanning an authentication setup code from an untrusted page
  • forgetting to protect recovery codes
  • leaving an old phone registered after giving it away
  • assuming every MFA method has identical security
  • using a weak reused password because MFA is enabled
  • failing to plan for a lost authentication device

A practical MFA checklist

For each important account, ask:

  1. Does this account offer multi factor authentication?
  2. Which authentication methods are available?
  3. Is a phishing resistant option available?
  4. Did I enable the strongest practical method I can maintain?
  5. Is my password still unique if the account uses one?
  6. Do I recognize how normal login requests appear?
  7. Would I know what to do with an unexpected approval request?
  8. Do I understand recovery?
  9. Are my recovery details current?

The main idea

Multi factor authentication adds another form of proof beyond a password or other single factor.

This can prevent many account takeovers when a password has been stolen.

Different authentication methods provide different levels of security.

Temporary codes and approval requests can help, but some can still be targeted by phishing.

Phishing resistant methods provide stronger protection when supported and practical.

Whichever method you use, protect recovery information, reject unexpected requests and keep the account's other security settings strong.

Continue learning

Review Complete Guide to Staying Safe Online for the wider Digital Safety framework.

Review How Strong Passwords and Passphrases Work if the account still uses a traditional password.

A later HubEgg lesson will guide you through enabling multi factor authentication safely.

Sources and further reading