MFA requires a user to verify their identity using more than one independent factor, typically something they know (a password), something they have (a device or security key), or something they are (a biometric). It substantially reduces the risk of account takeover from stolen or guessed credentials alone.
Frequently asked questions
Is MFA the same as two-factor authentication (2FA)?
2FA is a specific case of MFA using exactly two factors; MFA is the general term and can involve more than two.
Does MFA have to happen on every login?
No. Adaptive access can reserve step-up MFA for higher-risk sessions and skip it for low-risk, recognized ones.
Are passkeys a form of MFA?
Passkeys combine something you have (the device) and something you are (biometric unlock) in a single step, which satisfies MFA without a separate second prompt. See passkeys.
.avif)