Multi-Factor Authentication (MFA)
A security method that requires two or more independent proofs of identity before granting access to an account or system.
Definition
Multi-factor authentication (MFA) is a security control that requires a user to present two or more independent pieces of evidence, called factors, before access is granted. These factors fall into distinct categories: something you know (a password or PIN), something you have (a phone, hardware key, or authenticator app), and something you are (a fingerprint, face, or other biometric). Because the factors are independent, an attacker who steals one of them, such as a password, still cannot log in without also defeating the second factor. MFA is one of the most effective and widely recommended defenses against account takeover.
MFA works by adding a second checkpoint after the password step. When a user signs in, the system verifies the first factor (usually a password), then prompts for a second factor: a one-time code from an authenticator app, a push notification approval, a hardware security key tap, or a biometric scan. Only when both factors succeed is access granted. Not all MFA methods are equally strong. SMS and email codes can be intercepted or phished, push notifications can be defeated by 'MFA fatigue' attacks where attackers spam approval requests, while phishing-resistant methods such as FIDO2 hardware keys and passkeys bind the login to the legitimate website and cannot be relayed to a fake page.
MFA matters because passwords alone are a weak defense. Credentials are routinely stolen through phishing, leaked in data breaches, and reused across sites. A single compromised password can open the door to email, banking, and corporate systems. MFA breaks this chain: even with a valid password, the attacker is stopped at the second factor. For regulated organizations in Indonesia, MFA is increasingly expected under OJK and ISO 27001 access-control requirements, and it is a baseline expectation for protecting customer and employee data under UU PDP Law 27/2022.
MFA is strong but not invincible. Attackers adapt with real-time phishing kits that proxy the login session and capture both the password and the live one-time code, and with social engineering aimed at convincing users or help desks to approve fraudulent requests. This is why MFA should be paired with phishing-resistant methods where possible and with ongoing security awareness training, so users recognize when an MFA prompt they did not initiate is itself the attack.
At a glance
- Type
- Preventive control
- Also known as
- MFA, 2FA
How it works
- 1
First factor: the user enters something they know, usually a password or PIN.
- 2
Second factor prompt: the system then asks for something the user has or is, such as an authenticator code, a push approval, a hardware key tap, or a biometric scan.
- 3
Independent verification: both factors must succeed on their own, so a stolen password alone cannot unlock the account.
- 4
Method strength varies: SMS and email codes are the weakest, while FIDO2 hardware keys and passkeys resist phishing entirely.
- 5
Access granted: only once every required factor passes does the system unlock the account.
Key points
- Passwords alone are a weak defense since they are routinely phished, leaked in breaches, or reused
- Not every MFA method offers the same level of protection
- Phishing-resistant methods bind the login to the legitimate site so they cannot be relayed to a fake page
- MFA is increasingly expected under OJK and ISO 27001 access-control requirements
- Attackers now target MFA directly through real-time phishing kits and MFA fatigue
Best practices
- Enable MFA on every account that supports it, starting with email and financial systems
- Choose phishing-resistant methods such as FIDO2 hardware keys or passkeys where available
- Avoid SMS or email codes for high-value accounts when a stronger option exists
- Pair MFA with security awareness training so employees recognize unsolicited prompts as suspicious
- Treat any MFA request you did not trigger as a likely attack and report it immediately
Real-world example
A teller's password is exposed in a breach at an unrelated website. When the attacker tries to reuse it to log into the bank's HR portal, the system blocks the attempt because it also requires a one-time code from the teller's authenticator app, a code the attacker cannot generate.
How Claro helps
Claro helps organizations measure whether MFA is genuinely protecting them, not just whether it is switched on. Through realistic phishing simulations, including credential-harvesting and MFA-relay scenarios, Claro reveals which employees would approve an unexpected prompt or hand over a one-time code to an attacker. Those moments trigger just-in-time micro-training that teaches people to pause on unsolicited MFA requests, feeding into each user's risk score so security teams can target the individuals and departments where MFA habits are weakest.
Frequently asked questions
What is Multi-Factor Authentication (MFA)?
Multi-factor authentication (MFA) requires two or more independent proofs of identity to log in, such as a password plus a code or a passkey, so a stolen password alone is not enough for an attacker to get in.
What is the difference between MFA and two-factor authentication (2FA)?
2FA is a specific case of MFA that uses exactly two factors, usually a password plus one other proof. MFA is the broader term and can involve two or more factors from different categories.
Which MFA method offers the strongest protection?
Phishing-resistant methods such as FIDO2 hardware security keys and passkeys are strongest, since they cryptographically bind the login to the legitimate site. SMS and email codes are the weakest, since they can be intercepted or phished.
Can MFA be bypassed?
Yes. Real-time phishing kits can relay a valid one-time code within seconds of it being entered, and MFA fatigue attacks spam push approvals until a tired user accepts one. This is why phishing-resistant methods and awareness training both matter.
Does having MFA switched on mean an organization is protected?
Not automatically. The protection depends on which method is used and whether employees recognize an unsolicited prompt as a red flag rather than approving it out of habit.
Related terms
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Credential Harvesting
Credential harvesting is the theft of usernames, passwords, and other login data, usually through fake login pages or deceptive messages, so attackers can access accounts and systems.
Social Engineering
The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.
Security Awareness Training
Security awareness training is structured education that teaches employees to recognize and respond to cyber threats such as phishing, social engineering, and unsafe data handling.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo