openskills.info
Course Preview

Multi-Factor Authentication

Multi-factor authentication proves control of two or more distinct factor types, such as a password and a security key. It makes stolen passwords less useful, but its strength depends on the authenticators, enrollment, recovery, and protection against phishing.

itIdentity, access, and cryptography

Multi-Factor Authentication

Multi-factor authentication, or MFA, asks for evidence from more than one distinct factor type before a service grants access. The usual factor types are knowledge, possession, and inherence.

A password is knowledge. A phone, hardware token, or security key is possession. A biometric comparison is inherence. Two passwords are two steps, but they are still only knowledge. They do not make MFA.

MFA reduces the harm from a stolen password. It does not make an account impossible to take over. An attacker can still trick a user into relaying a code, flood a phone with approval prompts, steal a session, or abuse a weak recovery process.

Think in authentication paths

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.