Multi-factor authentication (MFA) is a process involving two or more steps. It is used to confirm that you have legitimate access to the resource or service that you want to use. If you have heard of 2FA, that is one form of MFA .
If you are wondering why a password alone is not enough, Microsoft’s statistics show that more than 99.9% of hacked accounts do not have MFA . In other words, if you use MFA combined with a strong password, you are less likely to have your account compromised.
How does MFA work?
In the MFA process, you make use of something that you know, something that you are, or something that you have:
- Something that you know: Username, pin, password, one-time codes.
- Something that you are: Biometric, like finger prints or facial recognition.
- Something that you have: An app based code generator (like MS Authenticator), app based login, or smart cards.
What kind of MFA is best (and worst)?
SMS codes are the least secure due to the risk of sim-swapping, an attack that tricks your mobile network provider into routing your calls and texts to a fraudster, including your security codes and password resets.
Receiving one-time codes via e-mail is slightly better, but it depends on your account security. If your email gets compromised, the attacker will see these one-time codes as well.
The most secure method, is app-based MFA. When you combine something that you know (your password) and something that you have (the authenticator app on your phone), the account remains secure even if your password gets leaked or cracked.
These are some of the more popular, free, and easy to use authenticator apps:
πΊπΈ Microsoft Authenticator (best integration with MS 365)
πΊπΈ Google Authenticator
πΊπΈ Authy
πΈπͺ/πΊπΈ Yubico Authenticator
π¨π Proton Authenticator (open source, strict privacy laws)
π³π±/ π©πͺ Aegis Authenticator (open source)
Depending on which you choose, the initial setup may vary a little. Look for explainer videos and read the product guides for more information if you are unsure.
Setting up and using your MFA app
Once you have decided on which app to use and downloaded it, you need to enable MFA/2FA on your accounts – starting with the most sensitive and important ones.
When enabling MFA on a website (like LinkedIn or Netflix), this is usually how it goes:
- Once you have opted to use MFA on your account, the site you are on will display a QR code.
- When you open your MFA app, click to add an account, and scan the QR code displayed on the website to link the account.
- The next time you go on to that site, you enter your regular credentials (username, password), and receive a prompt asking you to verify with a MFA challenge. This could be a time-based one-time password (TOTP) that you need to enter on site, a push notification asking you to match a number shown on your screen or to approve the login.
- Once you have entered your credentials and either approved of the push notification or entered the TOTP on your app, you will be able to log on to the platform.
Below is a quick video that shows how easy this is to do with MS Authenticator:
The setup might seem like a hassle at first (especially if you are not that fond of tech), but in the long run it may save you from a heap of trouble. When nearly all hacked accounts lack MFA, adding this to your accounts is one of the most effective things you can do to improve your account security.
Take our quick quiz to see if you remember the basics
Results
Well done!
Not quite there yet. You might want to read the lesson again.




