Skip to main content

Magnum Computer Services

Multi-Factor Authentication Explained: What It Is, Different Types & Benefits

You hear about company security breaches all the time where customer and even employee login information was stolen and leaked online. That alone makes it hard to trust that hackers won’t be able to get into your system via user login credentials.

Then you have to factor in poor password hygiene. This includes using:

  • Short passwords
  • Weak passwords (e.g. containing lowercase letters only)
  • Common passwords (e.g. “admin” or “123456”)
  • Predictable patterns (e.g. “Password123”)
  • Reused passwords
  • Passwords shared with others in public or unsecured spaces

It’s all too easy for hackers to gain access to passwords these days, so additional cybersecurity solutions and measures are needed. This is where multi-factor authentication comes into play.

What is Multi-factor Authentication?

To start, authentication is a way to validate that a user is who they claim to be. In the real world, it’s like being asked for your driver’s license or for the key to your front door. When online, users verify their identity and right to enter a private space with a password or other identifiable information.

While the password was the long-reigning champ when it came to online authentication, it’s not enough anymore. If a user is going to access a digital space with private and/or sensitive data, they usually need to provide multiple methods of validation.

That’s what multi-factor authentication (or MFA) is for.

MFA authentication confirms a user’s identity by asking for two or more pieces of proof. The password is commonly the first checkpoint a user goes through. The second (and sometimes third or fourth) will use another method.

What’s the Difference Between 2-factor Authentication and Multi-factor Authentication?

In some cases, there is no difference between 2-factor authentication (2FA) and MFA.

In general, the authentication process looks like this:

  • The user reaches the login area.
  • They enter their username and password.
  • The system asks for an additional step (e.g. answer security question, biometric scan, or authenticator app code).
  • The system verifies the accuracy of the responses.
  • If they match up, the user gains access. If they don’t, the user is denied.

That’s both two-factor and multi-factor authentication.

Depending on the complexity of the second factor, an unauthorized user or hacker might be unable to break in. That said, for apps and systems with higher levels of security, a third or fourth authentication factor should be implemented to more confidently lock everything down. That would be an example of MFA that isn’t also 2FA.

What Are the Different Types of MFA?

We typically categorize the different kinds of MFA based on where the input comes from.

Knowledge Factors

This type of factor relies on the user’s personal knowledge. It includes:

  • Passwords
  • PINs
  • Security question answers

The problem with relying on a knowledge factor in addition to a password is that so much of our identities is online. Take the question “What’s your mother’s maiden name?”. That might be an easy enough one to crack if the user is friends with their mother on Facebook and she happens to go by her maiden name. Or if their relationship (and her name) can be found on a public record lookup site.

So, these types of factors should be used as the first line of defense or in cases where the data locked behind the login screen isn’t sensitive or valuable.

Possession Factors

This type of factor relies on something a user can obtain or do from one of their devices. For example:

  • One-time password texted or emailed to the user
  • Authenticator app code (from Google Authenticator, Microsoft Authenticator, or Cisco Duo)
  • Mobile app or wearable device confirmation
  • Hardware security key (like a USB)

The user usually has to be in possession of their mobile device in order for this method to work. Because of this, you may need to give them a way to back out and try another one if they don’t have their device on hand.

While this is more secure than a knowledge factor, possession factors are hackable too if an unauthorized user takes possession of the device.

Inherence Factors

This type of factor is dependent on the user’s biometrics. For example:

  • Thumb or fingerprint
  • Face ID
  • Voice recognition

This type of authentication is more secure than the first two as it requires the user’s unique physical features to confirm their identity.

However, this method isn’t entirely secure as all it takes is for someone to place the device in front of the user’s face or against their finger. Also, with the proliferation of selfies that people post online, some hackers are able to game the system by using those photos.

Contextual or Behavioral Factors

This type of factor takes into account where the user is or what they’re using to access the system. For example:

  • IP address verification
  • Corporate VPN login
  • Trusted and registered device usage

This requires the user to be consistent in their methods for accessing the system. If you have employees who work on the go or who use multiple devices and networks, then this could be problematic for them.

While not entirely hack-proof, this kind of authentication is as close as it gets out of all four types. If you have a ton of sensitive information hidden behind the login screen, this would make for a great second or third factor.

It’s worth mentioning that CAPTCHA used to be the standard when it came to behavioral factors. But it really only works if you’re trying to keep machines from getting inside your system. Unauthorized persons will still be able to type out the code or select motorcycles in the photos. So, be sure you only use this method for restricting bot traffic (like on website contact forms).

What Are the Benefits of Using MFA in Your Business?

As consumers, we don’t have a lot of choice when it comes to using MFA. Some platforms require it for entry, so we’ve all just gotten used to it.

But as a business owner, you have a choice. If you’ve determined you have data, assets, or something else you don’t want unauthorized users or nefarious actors to access, then MFA is a must.

Here are the reasons why you should implement it:

  • It keeps poor password hygiene practices from compromising your business.
  • It reduces the likelihood of a security breach through the login entry point.
  • It sets a good first impression with users that you take their security and privacy seriously.
  • It reinforces the importance of cyber security within your team.
  • It’s essential for enabling a mobile workforce.
  • It can keep users from trying to access your system if they’re not in a secure place (e.g. using a friend’s device, working over public wi-fi, etc.).
  • If someone loses their device, MFA at the lock screen can keep others from breaching it.

Just make sure that you don’t go overboard when implementing your MFA system.

We’re all feeling a little fatigued from the many times a week (or even day) when we have to authenticate our identities. So, only add as many factors as you need. And choose factors that make sense for the type of user accessing your system as well as the data that sits within it.

Wrapping Up

Stay tuned for our next post where we’ll discuss where to use multi-factor authentication in your business and how to set it up. We’ll also explore some popular multi-factor authenticator apps you and your team can use to secure access whether you’re working from inside or outside of the office.

In the meantime, download our 58-point cybersecurity checklist, which includes 57 other tips for securing your business.

Subscribe for More Content

Are you a business owner or IT manager looking to optimize your company’s IT systems? Subscribe for more useful tips and insights.