Controls

What is multi-factor authentication?

Multi-factor authentication (MFA) is an access control that requires two or more independent forms of evidence before granting a sign-in: something the user knows, such as a password; something they have, such as a phone or hardware key; or something they are, such as a fingerprint. It is designed so that a stolen password alone is not sufficient to access an account.

Written and reviewed by , Group Technical DirectorLast reviewed 30 July 2026

At a glance

Also called
Two-factor authentication (2FA), two-step verification
Factor types
Knowledge, possession, inherence
Strongest common method
FIDO2 / passkeys (phishing-resistant)
Weakest common method
SMS one-time codes
Cyber Essentials
Required on cloud services and administrative accounts

Methods ranked by resistance to attack

Not all MFA offers equal protection. The differences matter because attackers have adapted to the weaker methods.

  • FIDO2 security keys and passkeys — cryptographically bound to the legitimate site, so phishing proxies cannot relay them. Strongest available option.
  • Authenticator app with number matching — the user enters a number shown on the sign-in screen, which defeats blind approval of fraudulent prompts.
  • Push notification approval — convenient, but vulnerable to MFA fatigue attacks where users approve out of habit or irritation.
  • Time-based one-time codes from an app — reasonable, but can be captured by an attacker-in-the-middle phishing page.
  • SMS codes — better than nothing, but vulnerable to SIM swap, interception and phishing relay.

How attackers bypass MFA

MFA substantially reduces account compromise but is not absolute. Attacker-in-the-middle phishing kits proxy the legitimate login page, capture both the password and the one-time code, and use them within their validity window. Session token theft skips authentication entirely by stealing the cookie issued after a successful sign-in. MFA fatigue attacks flood a user with push prompts until one is approved.

Phishing-resistant methods — passkeys and FIDO2 keys — defeat the first and third of these outright, which is why they are recommended for administrative accounts in particular.

Where it should be enforced

MFA should apply to every externally accessible service: email and Microsoft 365 or Google Workspace, VPN and remote access, accounting and payroll systems, banking, cloud administration consoles, and any SaaS platform holding client data.

Administrative accounts warrant the strongest available method. Legacy authentication protocols that bypass MFA entirely should be blocked, since they are a routine route around an otherwise well-configured policy.

Sources

The definitions and figures on this page are drawn from the primary sources below. Where guidance changes, the source takes precedence over our summary of it.

  1. Multi-factor authentication for online servicesNational Cyber Security Centre
  2. NIST SP 800-63B: Digital Identity Guidelines — AuthenticationNational Institute of Standards and Technology
  3. Cyber Essentials Requirements for IT InfrastructureIASME Consortium

FAQ

What is multi-factor authentication — common questions

Direct answers to the questions asked most often about this topic.

Is SMS-based MFA good enough?

+

SMS is considerably better than a password alone and still blocks the large volume of automated credential-stuffing attacks that rely on reused passwords. Its weaknesses are specific: SIM swap fraud, where an attacker persuades a mobile operator to transfer a number; interception in some network conditions; and phishing pages that relay the code in real time. For general staff accounts, SMS is an acceptable interim step if the alternative is nothing. For administrators, finance staff and anyone able to move money or change bank details, an authenticator app with number matching or a hardware key is the appropriate standard.

Does Cyber Essentials require multi-factor authentication?

+

Yes. Current Cyber Essentials requirements mandate multi-factor authentication on cloud services, and specifically on administrative accounts. The requirement applies to services accessible from the internet — Microsoft 365, Google Workspace, cloud-hosted line-of-business applications and remote access. Missing or partially deployed MFA is one of the most common reasons organisations fail their first assessment attempt, typically because it is enabled for some users but not enforced for all, or because legacy authentication protocols remain enabled and allow sign-in without it.

What is an MFA fatigue attack?

+

An MFA fatigue or prompt-bombing attack occurs when an attacker already holds a valid password and repeatedly triggers authentication requests, sending a stream of push notifications to the legitimate user's phone. The intent is that the user eventually approves one — through confusion, irritation, or while distracted — often at an inconvenient hour. Several significant breaches have started this way. The countermeasure is number matching, where the user must type a number displayed on the sign-in screen rather than simply tapping approve, combined with alerting on repeated failed attempts. Staff should also be told explicitly to report unexpected prompts.

What are passkeys, and are they replacing MFA?

+

Passkeys are cryptographic credentials stored on a device or in a password manager, based on the FIDO2 standard. Rather than transmitting a shared secret, the device proves possession of a private key to the specific site it was registered with, and unlocks it with a biometric or PIN. Because the credential is bound to the legitimate domain, a phishing site cannot use it — which defeats the attacker-in-the-middle technique that captures one-time codes. Passkeys are not replacing MFA so much as becoming its strongest implementation, combining possession and inherence in a single, phishing-resistant step.

Will MFA disrupt staff productivity?

+

Poorly configured MFA does. Well-configured MFA rarely does. The disruption people remember usually comes from prompting on every sign-in, on every device, several times a day. Conditional access policies avoid that by evaluating risk: trusted, compliant, managed devices on known networks can be granted longer sessions, while sign-ins from unfamiliar locations, unmanaged devices or anomalous conditions trigger a challenge. With sensible policy, most staff authenticate fully once every few days. The practical cost is close to negligible relative to the compromise it prevents.

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way