What is multi-factor authentication?

If you only ever do one thing from this whole site, make it this one. Multi-factor authentication is the closest thing security has to a free lunch.

// overview

Two locks instead of one.

Multi-factor authentication (MFA, sometimes called two-factor or 2FA) means proving who you are in more than one way before you get in. Usually that's something you know (your password) plus something you have (your phone).

The reason it matters is simple. Passwords leak. They leak in enormous breaches at companies you'd forgotten you had an account with, and those lists get traded and tested against every other service. If your password is the only thing standing between a stranger and your email, then the day that list includes you is the day you have a very bad week.

With MFA switched on, a leaked password is not enough. They'd also need the phone in your pocket. That single extra step stops the overwhelming majority of account takeovers, which is why every bank, every government service and every serious email provider now offers it.

// how it works

The three kinds of proof.

// doing it properly

Not all second factors are equal.

If you have the choice, use an authenticator app rather than a text message. Apps like Microsoft Authenticator, Google Authenticator or Authy generate a code on your device that never travels over the phone network.

SMS codes can be intercepted through what's called SIM swapping, where someone convinces your telco to move your number onto their SIM. It's rare, and it's mostly aimed at people with something worth stealing. But an app is no harder to use, so you may as well take the better option.

That said: SMS-based MFA is vastly better than no MFA at all. If the choice is between a text message and nothing, take the text message and move on with your day.

// the objection

"Won't this be a nuisance?"

Less than you'd think. On devices you use regularly you'll typically be asked once every thirty days or so, not every time you log in. The friction lands almost entirely on someone logging in from a country you've never visited.

The genuine risk isn't inconvenience, it's locking yourself out. This is the part people get wrong, and it's why we always set up a backup method at the same time: printed recovery codes, a second device, or a trusted phone number. Ten extra minutes at setup saves a very stressful afternoon later.

If you'd rather someone just did it with you across email, banking and your business systems in one visit, that's a standard callout for us. We'll set up the backups properly and leave you with the recovery codes somewhere sensible.

// questions

Good questions, straight answers.

What if I lose my phone?

This is exactly why backup codes exist. When you switch MFA on you're offered a list of one-time recovery codes, print them and keep them somewhere safe, not on the computer. Adding a second device as a backup method is the other half of the answer.

Is MFA the same as two-factor authentication?

Near enough. Two-factor means exactly two proofs; multi-factor means two or more. In everyday use people use the terms interchangeably and nobody will misunderstand you.

My accountant says we need it for insurance. Is that right?

Increasingly, yes. A lot of cyber insurance policies now list MFA as a condition of cover, particularly for email and remote access. Worth reading your policy carefully, a claim declined on a technicality is an expensive surprise.

Can you set this up for our whole team?

Yes, that's a common job for us. We'll roll it out across your Microsoft 365 or Google Workspace accounts, sort the backup methods so nobody gets locked out, and spend twenty minutes showing everyone how it works.

$ inspyred --book-a-callout

Got a question about this?
Ask a human.

Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.

Hours
By Appointment · 7 days
Service area
Toowoomba & the Darling Downs
Service style
Mobile: we come to you