Part of: CIAMLast updated 18 August 2026 · 1 min read

What is multi-factor authentication (MFA)?

MFA requires a user to verify their identity using more than one independent factor, typically something they know (a password), something they have (a device or security key), or something they are (a biometric). It substantially reduces the risk of account takeover from stolen or guessed credentials alone.

Frequently asked questions

Is MFA the same as two-factor authentication (2FA)?

2FA is a specific case of MFA using exactly two factors; MFA is the general term and can involve more than two.

Does MFA have to happen on every login?

No. Adaptive access can reserve step-up MFA for higher-risk sessions and skip it for low-risk, recognized ones.

Are passkeys a form of MFA?

Passkeys combine something you have (the device) and something you are (biometric unlock) in a single step, which satisfies MFA without a separate second prompt. See passkeys.

Building the integration, not choosing it?Definitions stop where implementation starts. The developer docs carry the API references, SDKs and SCIM endpoints.
Developer doc

Ready to move beyond legacy CIAM?

Definitions are the easy part. Go live in weeks with identity that governs AI agents, customers, and partners from one place.

Learn more