This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

Multi-factor authentication (MFA)

Information Security

Multi-factor authentication (MFA) is a method of identity verification in which the system requires confirmation from different protection categories, not just a login and password. Even if an attacker steals your password, they will not be able to log in without the second factor (an SMS code, fingerprint or physical key).

What is multi-factor authentication in simple words

Multi-factor authentication (MFA) is a method of identity verification in which logging into a system requires confirmation from different protection categories, not just a login and password. It is like two locks on a door: even if an attacker picks the key to one lock, the second one will stop them.

Multi-factor authentication (MFA): three factors Three MFA factors: knowledge (password, PIN code), possession (phone, token, SMS code) and inherence (biometrics: fingerprint, Face ID). Combining factors provides maximum protection. 49. MFA — factors Knowledge Password, PIN code Possession Phone, token Inherence Fingerprint, Face ID
Multi-factor authentication (MFA) — term diagram

The classic example is withdrawing cash at an ATM: to get money, you must insert a physical card (something you have) and enter a PIN code (something you know). In the digital world, MFA works on the same principle.

According to Microsoft statistics, using MFA blocks up to 99.9% of automated attacks and significantly reduces the risk of account compromise. Despite this, only about 30% of users enable two-factor authentication on their accounts. Read about other protection methods in the article Information security.

Three main authentication factors

Three main types of factors are used for authentication, which can be combined to create multi-factor protection:

  • Knowledge (something you know): Password, PIN code, answer to a secret question, code word. The most common, but also the most vulnerable factor — passwords can be guessed, stolen or caught sight of.
  • Possession (something you have): One-time code from SMS, push notification to a smartphone, authenticator application (Google Authenticator, Yandex Key), physical USB token (YubiKey, Rutoken) or smart card. This significantly increases security, since an attacker needs to physically take possession of your device.
  • Inherence (something you are): Biometric data — fingerprint, face scanning (Face ID), retina scan, voice or behavioral patterns. The most difficult factor to forge.

How MFA differs from 2FA

These terms are often confused, but there is an important difference between them:

  • 2FA (two-factor authentication): Uses exactly two factors from different categories (for example, password + SMS code). This is a special case of MFA, the most common in practice.
  • MFA (multi-factor authentication): Uses two or more factors (for example, password + fingerprint + push notification). MFA can include three or more factors, which provides the maximum level of security.

Read about the difference between authentication and authorization in the article Authentication.

How MFA works in practice

The typical multi-factor authentication process when logging into an account looks like this:

  1. You enter your login and password (Factor No. 1 — Knowledge).
  2. The system sends a code to your phone via SMS, a push notification, or generates a code in the authenticator application (Factor No. 2 — Possession).
  3. You enter the received code or confirm the login in the application.
  4. Login is allowed only after both stages are successfully passed. If an attacker stole your password but has no access to your phone — they will not be able to log in.

Read about MFA setup in the article OAuth.

Methods of implementing MFA

There are several methods of implementing MFA, each with its own advantages and disadvantages:

  • SMS and voice calls: The simplest and most popular way. The code comes to the phone via SMS or a voice call. Disadvantage — vulnerability to SIM swapping (when an attacker reissues a SIM card) and message interception.
  • Authenticator applications: Google Authenticator, Microsoft Authenticator, Authy, Yandex Key. Generate codes on the device, do not require the internet. Safer than SMS, since codes are not transmitted over the network.
  • Push notifications: The application sends a request to confirm login. It is enough to press “Yes” on the smartphone. Convenient and fast, but requires the internet on the device.
  • Hardware keys (U2F): Physical devices (YubiKey, Rutoken). The most reliable way — the key is physically connected to a USB port or via NFC. Resistant to phishing and remote attacks. Used in Google and other large companies.
  • Biometrics: Fingerprint, Face ID, iris scanner, voice biometrics. Convenient and safe, but requires a biometric sensor on the device.

Read about biometric security in the article Biometrics.

Risks and limitations of MFA

Despite its high effectiveness, MFA has some limitations that are important to consider:

  • Dependence on devices: If you lose the phone with the authenticator or SIM card, access may be lost. Always save the backup recovery codes that are issued when MFA is set up.
  • SIM swapping: An attacker can reissue a SIM card through the operator and intercept SMS with codes. Therefore, SMS codes are considered the least reliable method.
  • Phishing: Fake websites can imitate a request for a second factor. For example, an attacker can create a fake login page that requests an SMS code and intercepts it. Using hardware keys (U2F) protects against this.
  • Inconvenience: Requires additional time and actions on every login. However, this small inconvenience is compensated by a significant increase in security.

Read about digital hygiene in the article Digital footprint.

Frequently asked questions

What is multi-factor authentication in simple words?

This is a method of identity verification that requires confirmation from different categories: a password (something you know) + an SMS code (something you have) or a fingerprint (something you are). Even if the password is stolen, without the second factor you will not be able to log in. It is like two locks on a door — one lock can be broken, but two is already almost impossible. Read about other protection methods in the article Information security.

How does MFA differ from 2FA?

2FA (two-factor) uses exactly two factors (password + SMS code). MFA (multi-factor) — two or more factors (password + fingerprint + push notification). 2FA is a special case of MFA. If the system uses three factors, this is already MFA, not 2FA. Read about the difference between authentication and authorization in the article Authentication.

Which MFA method is the most reliable?

The most reliable are hardware U2F keys (YubiKey, Rutoken). They are physically isolated from the internet, not subject to phishing and do not require data transmission over the network. The second most reliable are authenticator applications (Google Authenticator, Yandex Key, Authy). SMS is the least reliable method due to vulnerability to SIM swapping and message interception. Read about choosing a method in the article Biometrics.

What is the main drawback of MFA?

Dependence on external factors (phone, internet, cellular communication). If you lose the phone with the authenticator or end up in a zone without communication, access may be lost. Therefore, it is important to save the backup recovery codes that are issued when MFA is set up. Store them in a reliable place (for example, in a safe) — they will help restore access if you lose the device. Read about backup in the article Data backup.

What is an example of multi-factor authentication?

A classic example is logging into internet banking: entering a login and password (knowledge) + confirmation via an SMS code or push notification in the mobile bank (possession). Another example is logging into a Google account using a password + a code from Google Authenticator + a fingerprint (already three factors). In Russian government systems, login via ESIA with confirmation by SMS and an electronic signature is used. Read about setup in the article OAuth.

How to enable MFA in popular services (Google, Yandex, VKontakte)?

In Google: Account settings → Security → Two-step verification → Follow the instructions. In Yandex: Account settings → Security → Two-factor authentication. In VKontakte: Settings → Security → Login confirmation. Usually you can choose a method: SMS, an authenticator application (Google Authenticator, Yandex Key) or push notifications. It is recommended to use an authenticator application — it is safer than SMS.

Is it mandatory to use MFA for government systems in Russia?

Yes, for many government systems in Russia the use of MFA is mandatory or strongly recommended. For example, the State Services portal (ESIA) uses two-factor authentication — a password + an SMS code or confirmation through the application. To access Electronic Budget, SMIV and other government information systems, MFA using an electronic signature and additional factors is also required. This complies with the requirements of 152-FZ and 187-FZ.

Was this information helpful?

Protect your network today

Leave a request — our information security specialists will help you select, configure and integrate multi-factor authentication (mfa) into your infrastructure. We will protect your data from threats.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm