IT & Cloud
MFA
Also called: Multi-Factor Authentication, 2FA
Authentication requiring two or more independent factors — something you know, have, or are — so a stolen password alone does not grant access.
MFA remains the highest return security control available, because credential theft through phishing is the most common initial access route. Enabling it on email and remote access blocks the overwhelming majority of opportunistic attacks outright.
Not all factors are equal. SMS codes are vulnerable to SIM swapping and push prompts to fatigue attacks, so app-based number matching or FIDO2 keys are the stronger choices — particularly for administrators, where one compromise reaches everything.
Related terms
- Entra ID
- Microsoft's cloud identity service — formerly Azure Active Directory — which authenticates users and devices and enforces access policy across Microsoft 365 and connected applications.
- Zero Trust
- A security model that treats no network as inherently safe, verifying identity, device health, and authorisation for every request rather than trusting anything inside a perimeter.
- Endpoint Security
- Protection on the device itself that detects malicious behaviour, contains it, and preserves the forensic trail — going beyond signature-based antivirus.
- Mobile Credential
- A door credential held in a phone's wallet or an app and presented over Bluetooth or NFC, replacing a plastic card or fob.
More IT & Cloud terms
Support305 in the press
All press coverageNeed this specified correctly?
Our engineers will review your drawings or quote and tell you exactly where MFA belongs in the design.
Talk to an engineer