What is multi-factor authentication?
If you only ever do one thing from this whole site, make it this one. Multi-factor authentication is the closest thing security has to a free lunch.
// overview
Two locks instead of one.
Multi-factor authentication (MFA, sometimes called two-factor or 2FA) means proving who you are in more than one way before you get in. Usually that's something you know (your password) plus something you have (your phone).
The reason it matters is simple. Passwords leak. They leak in enormous breaches at companies you'd forgotten you had an account with, and those lists get traded and tested against every other service. If your password is the only thing standing between a stranger and your email, then the day that list includes you is the day you have a very bad week.
With MFA switched on, a leaked password is not enough. They'd also need the phone in your pocket. That single extra step stops the overwhelming majority of account takeovers, which is why every bank, every government service and every serious email provider now offers it.
// how it works
The three kinds of proof.
- 01
Something you know
Your password or PIN. On its own this is the weakest factor, because it can be guessed, leaked in a breach, or handed over to a convincing scammer without you realising.
- 02
Something you have
Your phone, an authenticator app, or a small physical key. This is what most people add as their second factor, and it's where nearly all the benefit comes from.
- 03
Something you are
A fingerprint or your face. Convenient and increasingly common on phones and laptops, and genuinely hard for someone in another country to fake.
// doing it properly
Not all second factors are equal.
If you have the choice, use an authenticator app rather than a text message. Apps like Microsoft Authenticator, Google Authenticator or Authy generate a code on your device that never travels over the phone network.
SMS codes can be intercepted through what's called SIM swapping, where someone convinces your telco to move your number onto their SIM. It's rare, and it's mostly aimed at people with something worth stealing. But an app is no harder to use, so you may as well take the better option.
That said: SMS-based MFA is vastly better than no MFA at all. If the choice is between a text message and nothing, take the text message and move on with your day.
- Start with your email account, it's the master key to everything else
- Then your banking, then anything holding customer or payment data
- Prefer an authenticator app over SMS where the option exists
- Save the backup codes somewhere that isn't your computer
- Add a second device or a trusted contact so a lost phone isn't a disaster
// the objection
"Won't this be a nuisance?"
Less than you'd think. On devices you use regularly you'll typically be asked once every thirty days or so, not every time you log in. The friction lands almost entirely on someone logging in from a country you've never visited.
The genuine risk isn't inconvenience, it's locking yourself out. This is the part people get wrong, and it's why we always set up a backup method at the same time: printed recovery codes, a second device, or a trusted phone number. Ten extra minutes at setup saves a very stressful afternoon later.
If you'd rather someone just did it with you across email, banking and your business systems in one visit, that's a standard callout for us. We'll set up the backups properly and leave you with the recovery codes somewhere sensible.
// questions
Good questions, straight answers.
What if I lose my phone?
This is exactly why backup codes exist. When you switch MFA on you're offered a list of one-time recovery codes, print them and keep them somewhere safe, not on the computer. Adding a second device as a backup method is the other half of the answer.
Is MFA the same as two-factor authentication?
Near enough. Two-factor means exactly two proofs; multi-factor means two or more. In everyday use people use the terms interchangeably and nobody will misunderstand you.
My accountant says we need it for insurance. Is that right?
Increasingly, yes. A lot of cyber insurance policies now list MFA as a condition of cover, particularly for email and remote access. Worth reading your policy carefully, a claim declined on a technicality is an expensive surprise.
Can you set this up for our whole team?
Yes, that's a common job for us. We'll roll it out across your Microsoft 365 or Google Workspace accounts, sort the backup methods so nobody gets locked out, and spend twenty minutes showing everyone how it works.
$ inspyred --book-a-callout
Got a question about this?
Ask a human.
Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.