Multi-Factor Authentication
Multi-factor authentication proves control of two or more distinct factor types, such as a password and a security key. It makes stolen passwords less useful, but its strength depends on the authenticators, enrollment, recovery, and protection against phishing.
itIdentity, access, and cryptography | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - Multi-Factor Authentication
Multi-factor authentication is a security property of a login transaction: the service demanded evidence from two or more distinct categories of proof before it let you in. A password plus a code from your phone is MFA. Two passwords are just two passwords, because they are both things you know, and things you know are one factor.
The whole point is that stealing one secret stops being enough. A phished password, a guessed password, a reused password - none of them grant access on their own when a second, independent factor is in the way. That single idea reduces the blast radius of the credential breaches that dominate modern attacks.
Here is the part that surprises most people: the login screen is not where MFA matters most. It is where MFA is easiest to deploy and most visible to users, which is why it gets all the attention. The lifecycle stages that surround it - binding a new authenticator, recovering a lost device, replacing a compromised key, removing an old one - are where the real security decisions live. A help desk that can reset your MFA after a phone call backed only by your date of birth has quietly made your hardware security key a decoration.
The two ideas everything else hangs on are phishing resistance and lifecycle assurance. Phishing resistance means the authentication protocol is cryptographically tied to the real site domain, so a fraudulent page cannot capture a usable result. WebAuthn and FIDO passkeys do this; TOTP codes and push notifications do not. Lifecycle assurance means you apply the same level of scrutiny to account recovery and authenticator enrollment that you apply to the login itself, because an attacker who can complete either one does not need to beat your login at all.
If you remember only one thing a week from now, make it this: the question is not whether you have MFA enabled. The question is which path is easiest for an attacker to take over the account. Find that path. Then make it earn the assurance your risk requires.
Read the Don't Panic tab first to orient yourself. The Slides give you the conceptual map. Field Notes is where practitioners tell you what actually goes wrong. The Reference tab has the standards and guides you will want when you start making choices.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://pages.nist.gov/800-63-4/sp800-63b.html
Supports
- Authentication factors, authenticator types, and authentication assurance levels
- MFA through a multi-factor authenticator or two distinct factors
- Password, OTP, out-of-band, and cryptographic authenticator behavior
- Authenticator binding, replacement, recovery, and session management
- Phishing resistance, replay resistance, authentication intent, and WebAuthn verifier name binding
- Out-of-band authentication limits, push approval transaction binding, rate limiting, and PSTN risk indicators
- https://cheatsheetseries.owasp.org/cheatsheets/Multifactor_Authentication_Cheat_Sheet.html
Supports
- MFA selection, deployment, recovery, bypass, usability, and operational considerations
- https://www.w3.org/TR/webauthn-3/
Supports
- WebAuthn public-key credentials, relying parties, authenticators, registration, authentication, and origin-related behavior
- https://fidoalliance.org/passkeys/
Supports
- Passkeys as FIDO public-key credentials, password replacement, phishing resistance, and device-bound or synchronized options
- https://www.cisa.gov/resources-tools/resources/implementing-phishing-resistant-mfa
Supports
- Organizational implementation guidance for phishing-resistant MFA
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
Supports
- Scattered Spider MGM Resorts attack advisory, help-desk social engineering, and Okta MFA reset exploitation
- https://en.wikipedia.org/wiki/2023_MGM_Resorts_cyberattack
Supports
- MGM Resorts breach timeline, Scattered Spider methods, $100M financial impact, and help-desk vishing attack chain
- https://www.bleepingcomputer.com/news/security/uber-hacked-internal-systems-breached-and-vulnerability-reports-stolen/
Supports
- Uber MFA fatigue breach, push notification bombing, and Lapsus$ social engineering through WhatsApp
- https://www.rsa.com/resources/blog/multi-factor-authentication/beware-mfa-fatigue
Supports
- MFA fatigue attack patterns, number matching mitigation, and transaction context requirements
- https://www.breachsense.com/blog/okta-data-breach-case-study
Supports
- Okta 2022 and 2023 breaches, session token theft via HAR files, third-party vendor risk, and MFA bypass through session hijacking
- https://datatracker.ietf.org/doc/html/rfc4226
Supports
- HOTP HMAC-Based One-Time Password algorithm, event-driven OTP generation, and interoperable authenticator standardization
- https://datatracker.ietf.org/doc/html/rfc6238
Supports
- TOTP Time-Based One-Time Password algorithm, time-synchronized OTP, and software authenticator app foundation
- https://fidoalliance.org/overview/history/
Supports
- FIDO Alliance founding, UAF and U2F specification development, and timeline of open authentication standard adoption
- https://fidoalliance.org/specifications/download/
Supports
- FIDO U2F and FIDO2 specification downloads, WebAuthn and CTAP standards, and browser-based authentication protocols
- https://www.w3.org/TR/webauthn-1/
Supports
- WebAuthn Level 1 W3C Recommendation, browser-native public-key authentication API, and cross-origin authentication standard
- https://www.law.cornell.edu/patent/us4800508a
Supports
- Bellcore RSA-based authentication patent, foundational challenge-response public-key authentication system
- https://www.rsa.com/products/securid
Supports
- RSA SecurID hardware token platform, time-synchronized OTP, and enterprise MFA deployment history
- https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-id
Supports
- Microsoft Entra ID identity provider, conditional access policies, workforce MFA, and passkey registration
- https://www.okta.com/
Supports
- Okta cloud identity provider, adaptive MFA, passkey support, and SSO integration
- https://workspace.google.com/
Supports
- Google Workspace identity platform, MFA policies, passkey sign-in, and Advanced Protection Program
- https://www.keycloak.org/
Supports
- Keycloak open-source identity server, TOTP, WebAuthn, recovery codes, and identity provider brokering
- https://auth0.com/
Supports
- Auth0 developer identity platform, MFA, passkeys, adaptive authentication, and customer-facing auth integration
- https://duo.com/
Supports
- Duo Security Cisco MFA platform, zero-trust access, device visibility, and VPN/SSO second-factor integration
- https://www.yubico.com/
Supports
- Yubico YubiKey hardware security keys, FIDO2 WebAuthn, and cryptographic domain-bound authentication
- https://www.ftsafe.com/
Supports
- Feitian hardware security keys and OTP tokens, FIDO2, smart card interfaces, and multi-form-factor authenticators
- https://safety.google/authentication/
Supports
- Google Authenticator TOTP app, time-based one-time codes, and cross-platform possession factor
- https://www.microsoft.com/en-us/security/business/identity-access/microsoft-authenticator
Supports
- Microsoft Authenticator app, TOTP, push with number matching, and passwordless FIDO2 sign-in
- https://www.twilio.com/en-us/verify
Supports
- Authy cross-device TOTP authenticator, multi-device code synchronization, and recovery convenience
- https://1password.com/
Supports
- 1Password passkey and password manager, FIDO credential storage, cross-platform passkey access, and team management
- https://www.dashlane.com/
Supports
- Dashlane password manager with passkey storage, FIDO credential autofill, and cross-platform passkey adoption
