Guide
Glossary
Multi-factor authentication (MFA)
Multi-factor authentication (MFA) is a login check that asks for two or more different kinds of proof before granting access: something you know, such as a password; something you have, such as a phone or security key; or something you are, such as a fingerprint. A stolen password alone is then not enough to get in. MFA is one of the eight strategies in ASD's Essential Eight. ASD recommends phishing-resistant methods, such as passkeys, security keys and smart cards, because codes sent by text message or typed from an app can still be captured by a fake login page.
Also called MFA, two-factor authentication, 2FA
Last updated:
Example
In an accounting firm
During tax time, an employee at a 30-person accounting firm enters their Microsoft 365 password on a fake login page. Because the firm requires phishing-resistant MFA, such as a passkey, for email, the practice management system and its AI tools, the password alone does not let the attacker in. The firm resets the password and checks the sign-in log.
Guides that explain it in context
Secure by design. Set up correctly. Fully managed.
Talk to us before you commit to anything
Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.
