technology
What multifactor authentication protects—and what it does not
MFA makes a stolen password less useful, but the method you choose and the way you respond to prompts still matter.
Published ; updated
A password is one factor: something you know. Multifactor authentication MFA requires another type of proof, such as something you possess or a biometric. If an attacker steals your password, that additional check can stop the login. Not all MFA methods resist the same attacks. Security keys and passkeys based on FIDO/WebAuthn are designed to resist credential phishing because they bind authentication to the legitimate site. App codes and push notifications add protection, but a convincing fake page or repeated approval prompts can still trick a user. SMS codes are generally better than a password alone, yet they depend on the security of the phone account and network. Use the strongest option each service supports. Start with email, banking, password managers, cloud storage, social accounts, and administrator access. Store recovery codes somewhere protected and separate from the device you use to sign in. Review recovery email addresses and phone numbers, because a weak recovery path can bypass a strong login method. MFA does not make every prompt safe. Never approve a login you did not start. Open the service through a trusted bookmark or app rather than a link in an unexpected message. Keep devices and browsers updated, remove accounts you no longer use, and review active sessions after a suspicious event. CISA recommends requiring MFA and moving toward phishing resistant methods. The practical goal is layered security: a unique password, strong MFA, secure recovery, careful prompt handling, and routine session review. Sources CISA: Require Multifactor Authentication https://www.cisa.gov/audiences/small and medium businesses/secure your business/require multifactor authentication CISA: More than a Password https://www.cisa.gov/more password