Multi-Factor Authentication
Understand the factors
Authentication asks you to prove who you are. Multi-factor authentication (MFA) combines different kinds of proof.
- Something you know — a password or PIN
- Something you have — a phone app, hardware security key, or one-time code
- Something you are — a biometric such as a fingerprint unlock on your device
Choose stronger methods when you can
Authenticator apps and hardware security keys are generally stronger than SMS codes, because text messages can be intercepted or redirected in some scams. SMS MFA is still better than password-only access for many accounts.
Turn it on for high-value accounts
Enable MFA first on email, banking, work or school portals, cloud storage, and social accounts that can reset other services. Save backup codes in a safe place so you can sign in if you lose your phone.
Watch for MFA fatigue and fake prompts
If you receive unexpected approval requests, deny them, change your password from a device you trust, and review recent sign-ins. Legitimate services will not ask you to read a code aloud to a stranger on the phone.
Comments
One comment per signed-in account. Comments are saved with this page’s URL.