Multi-factor authentication, sometimes called two step verification, is the single most effective thing most businesses can do to protect their accounts. It adds a second proof of who you are, usually a code or a tap on your phone, on top of your password. Even if a scammer steals your password, they are stopped at that second step, which blocks the vast majority of account takeovers.
What the factors actually are
The idea is to combine something you know (your password) with something you have (your phone or a security key) or something you are (a fingerprint or face). Needing two different kinds means one stolen piece is not enough on its own.
Why it stops most attacks
Most account takeovers rely on a stolen or guessed password. MFA breaks that, because the attacker would also need the physical second factor, which they usually do not have. Turning it on is one of the highest value security steps for the least effort.
Not all methods are equal
An authenticator app or a physical security key is stronger than a code sent by text, because text messages can be intercepted or redirected. Text based codes are still far better than no MFA at all, so use them if that is what an account offers.
Turn it on for the important accounts first
Start with email, banking, your Microsoft 365 or Google account, and any tool holding customer or payment data. These are the accounts an attacker wants most, so they are where MFA earns its keep.
How to set it up
Look in the security or sign in settings of each account for two step or multi factor authentication, then follow the prompts, usually scanning a code with an authenticator app. Save the backup or recovery codes it gives you somewhere safe, so a lost phone does not lock you out.
Red flags to watch for
- Important accounts, especially email, still protected by a password alone.
- Being asked to approve an MFA prompt you did not trigger, which can mean someone has your password.
- Anyone, including a caller claiming to be support, asking you to read out your MFA code.
- No backup or recovery codes saved, so a lost phone means being locked out.
- MFA switched off to make life easier after a few prompts.
- The same phone used for both the password reset and the MFA code, with no backup method.
Check yourself
0/41.A scammer has stolen your email password in a data breach. You have multi-factor authentication switched on. What happens when they try to log in?
2.Your phone buzzes with an MFA approval request, but you were not trying to log in to anything. What should you do?
3.Which MFA method is generally the most secure?
4.When you set up MFA, an account gives you a set of backup or recovery codes. What should you do with them?
This is general guidance, not a substitute for advice on your specific setup. Want a hand putting it into practice? Talk to us or see our care plans.
