GRIDINSOFT HELP CENTER

Multi-Factor Authentication (MFA): Methods and Setup

Multi-factor authentication (MFA) requires evidence from at least two different factor categories before granting access. It protects an account when a password is guessed, reused, or exposed in a breach.

What counts as a separate factor?

  • Something you know: a password or PIN.
  • Something you have: a security key, trusted device, smart card, or authenticator.
  • Something you are: a fingerprint, face, or another biometric characteristic.

Two passwords are still one factor because both are things you know. A password plus a one-time code from a separate device uses two categories.

MFA methods from stronger to weaker

  1. FIDO2 security keys and passkeys: bind authentication to the real site and are designed to resist phishing.
  2. Authenticator apps: time-based codes are useful, while number-matching push approval reduces accidental acceptance.
  3. SMS or voice codes: better than a password alone, but vulnerable to SIM-swap, message interception, and convincing phishing pages.
  4. Email codes: depend on the security of the same email account and are usually a weaker recovery option.

Biometrics on a device normally unlock a locally protected credential; the service does not need to receive a copy of the fingerprint or face image.

How attackers try to bypass MFA

  • A phishing page relays a password and one-time code in real time.
  • MFA fatigue sends repeated push prompts until a user approves one.
  • Help-desk social engineering attempts to register a new device or reset factors.
  • Stolen session cookies bypass a new sign-in prompt.

Always open the service directly instead of using a sign-in link from an unexpected message. See Phishing for common warning signs.

Safe setup checklist

  • Enable MFA first on email, password managers, banking, cloud storage, and administrator accounts.
  • Prefer a passkey or security key where available.
  • Register a second secure method and store recovery codes offline.
  • Never approve a prompt you did not initiate; report repeated prompts immediately.
  • For organizations, require MFA centrally and protect enrollment and recovery with identity verification.

MFA greatly reduces account takeover, but it does not replace unique passwords, software updates, session monitoring, or careful recovery procedures.

Helpful?

Glossary (0-9, A-Z)

Still can’t find an answer?

Send us a ticket and we will get back to you.

Submit a ticket