Multi-factor authentication (MFA) is an authentication method that requires more than one type of factor to verify a user's identity (opens in new tab): something you know, such as a password; something you have, such as a hardware key or enrolled device; and something you are, such as a fingerprint.
The factors must come from different categories, so a password paired with a security question is still a single-factor type and does not qualify as MFA under NIST SP 800-63B-4 (opens in new tab), the standard that governs the definition.
How multi-factor authentication works
With MFA, a login proceeds in stages (opens in new tab): the user presents a first factor, usually a password, and the verifier challenges for a second factor of a different type before issuing a session. If attackers compromise one authenticator, a second uncompromised factor still blocks password-only access under the second authentication requirement (opens in new tab).
The authentication method (opens in new tab) sets the whole system's strength. An employee signing in to a SaaS application enters a password, then taps a FIDO2 hardware key; the key signs a cryptographic challenge (opens in new tab) bound to the service's domain, so a lookalike login page (opens in new tab) on a spoofed domain receives no valid signature.
A TOTP authenticator app works differently: it generates a six-digit code the user types in, proving possession of the enrolled device, but a fake page can capture and relay (opens in new tab) that code. Once authentication completes, the service issues a session cookie or token that stays valid (opens in new tab) without a new MFA challenge.
Why multi-factor authentication matters
For regulated organizations, MFA is now mandatory, not optional. Beginning November 1, 2025 (opens in new tab), any individual accessing any information system of a covered entity must use MFA under the NYDFS cybersecurity regulation, and NYDFS has already cited missing MFA as a control failure in enforcement actions (opens in new tab).
Under PCI DSS v4.0.1, all access into the cardholder data environment must use MFA as of March 31, 2025 (opens in new tab), and DoD contractors must use it at CMMC Level 2 under the final rule (opens in new tab) effective December 16, 2024. Cyber insurance carriers now require MFA across remote access (opens in new tab), cloud applications, VPNs, and privileged accounts.
MFA's effectiveness now drives attackers to engineer bypasses (opens in new tab): adversary-in-the-middle campaigns (opens in new tab) steal MFA credentials and session cookies (opens in new tab) in real time. Accounts without MFA stay exposed to plain credential theft (opens in new tab), because stolen passwords alone (opens in new tab) open any account that lacks a second factor and can lead to a data breach (opens in new tab).
Types of multi-factor authentication
MFA methods range in strength, from phishing-resistant options at the top to SMS at the bottom:
- FIDO/WebAuthn and passkeys (phishing-resistant). They bind the credential to the legitimate service's domain and answer a cryptographic challenge, so a spoofed page gets no reusable signature. Because they use no push approval or phone-network codes, they also resist push bombing, SS7 interception, and SIM swapping. Organizations should deploy passkeys wherever platforms support them (opens in new tab).
- PKI-based MFA (phishing-resistant). Smart cards such as PIV/CAC provide certificate-based authentication but require mature identity management and PKI infrastructure.
- Authenticator apps and OTP tokens (intermediate). Time-based codes resist push bombing and SIM swap, but a fake page can relay a code the user types before it expires.
- Push with number matching (intermediate). Entering a number from the login screen into the app blocks push bombing (opens in new tab). CISA treats it as an interim step (opens in new tab) until phishing-resistant methods are in place.
- Push without number matching (weak). Susceptible to MFA fatigue attacks (opens in new tab), where an attacker floods a user with prompts until one is approved; a simple approve-the-prompt authenticator no longer meets requirements (opens in new tab).
- SMS and voice OTP (weakest). Attackers defeat these through SIM swapping, SS7 attacks, and real-time relay. SMS/PSTN authenticators face restrictions (opens in new tab), and organizations should disable SMS fallback (opens in new tab) once users enroll stronger methods.
How to harden multi-factor authentication
Prioritize the following MFA controls:
- Deploy phishing-resistant methods first. Give them to administrators and other privileged users, then remove weaker fallback options once users enroll stronger ones. Attackers run downgrade attacks (opens in new tab) that force the authentication flow back to a phishable factor, so a registered SMS fallback keeps the door open.
- Cover every account. That includes legacy and non-production systems (opens in new tab). Block legacy authentication protocols (opens in new tab) that cannot enforce MFA, and audit test tenants, remote-access portals, and third-party integrations for gaps.
- Number-match every push. Turn on number matching (opens in new tab) for any push-based MFA still in use.
- Treat MFA resets as privileged events. Scattered Spider (opens in new tab) and similar groups call IT help desks, impersonate employees using publicly available personal data (opens in new tab), and talk agents into resetting passwords (opens in new tab) and MFA tokens. Require verification before resets (opens in new tab) or new device enrollment, log every request, and route privileged-account and executive resets to a specialized queue with callback verification.
- Watch the session after authentication. Attackers replay stolen session cookies (opens in new tab) and OAuth tokens to reuse a completed login without another MFA challenge.
Token binding (opens in new tab), short token lifetimes, and high-risk re-authentication (opens in new tab) limit the damage.
How Doppel helps
These controls harden MFA from the inside, but the attacks that route around it live outside your network. Doppel is the AI-native Social Engineering Defense (SED) (opens in new tab) platform that unifies Digital Risk Protection (DRP) (opens in new tab) and Human Risk Management (HRM) (opens in new tab), and it goes after the fake login pages, spoofed calls, and help desk pretexts that make MFA bypasses work.
The Doppel Threat Graph (opens in new tab) detects that infrastructure across domains, social, ads, and telco and correlates it into campaign-level views (opens in new tab), and its agentic AI executes takedowns to dismantle it at the source. The same campaign data closes the loop with internal defenses: teams convert any detected campaign into a multi-channel Simulation (opens in new tab) in one click, recreating help desk resets and OTP-readback tactics, and Security Awareness Training (opens in new tab) routes follow-up content by employee results.
Request a demo (opens in new tab) to get started.
Frequently asked questions about multi-factor authentication
What is the difference between MFA and 2FA?
The terms are synonymous in practice and map to the same definition in NIST's 2FA glossary (opens in new tab) and CISA's MFA guidance (opens in new tab). Technically, two-factor authentication (2FA) means exactly two factors, while multi-factor authentication (MFA) means two or more, so 2FA is a subset of MFA. In both, the factors must come from different categories, such as a password plus a hardware key.
What is phishing-resistant MFA?
Phishing-resistant MFA uses methods that block credential relay to a fake domain. Two method families qualify (opens in new tab): FIDO/WebAuthn (passkeys and hardware security keys) and public key infrastructure, or PKI (smart cards). They bind the credential to the legitimate service's domain, answer a cryptographic challenge, and keep authentication codes out of login forms, so a spoofed site captures no reusable credential. Codes from SMS, authenticator apps, and hardware tokens stay vulnerable to real-time relay (opens in new tab).
What is an example of a multi-factor authentication bypass attack?
Help desk social engineering (opens in new tab) can replace an MFA factor (opens in new tab) with one an attacker controls. The attacker calls an IT help desk, impersonates a real employee using publicly available details, and persuades staff to reset the password and MFA, then enrolls a device they control as the new factor. In June 2025, the FBI warned that Scattered Spider was bypassing MFA (opens in new tab) in attacks on the aviation sector by "convincing help desk services to add unauthorized MFA devices to compromised accounts." Because it swaps the legitimate factor instead of defeating the cryptography, this route bypasses even phishing-resistant MFA.
