Account security
What Is Multifactor Authentication?
MFA asks for a second proof besides the password. This guide explains the idea in plain English and shows how to turn it on without handing codes to a stranger.
The plain-English version
You already use a version of this at an ATM. The card is something you have. The PIN is something you know. Online MFA is the same idea with different objects. Common second factors:
CISA tells families that a password is not enough and that a second layer — text, email, app, biometrics, or, best, a FIDO security key — gives the service more confidence that it is you. Enable it on email, social, shopping, financial, and even streaming accounts.
- A prompt or one-time code in an authenticator app
- A passkey saved in the phone, computer, or password manager
- A physical security key you tap or plug in
- A code sent by text message or voice call
- A push notification that asks you to approve a login
Stronger and weaker methods
Not every second factor is equal. Usually stronger: a hardware security key, a passkey, or an authenticator app that shows a number you must match. These are harder to steal with a fake login page. Often weaker, still better than nothing: a code sent by SMS or a voice call. The code can be intercepted if someone takes over the phone number or tricks you into reading it aloud. CISA’s business and household material ranks methods from more secure to less secure and treats SMS as a fallback when better options are missing. NIST’s digital identity guidelines also separate a memorized password from authenticators that resist phishing. You do not need the standard numbers. You need the shopping rule: if the account can reset your life, prefer the method that cannot be forwarded in a text.
What MFA does not do
MFA is not magic.
Attackers now send fake “approve this login” floods. If a prompt appears and you are not logging in, deny it, then change the password on the official site. Do not tap Allow to make the notifications stop.
- It does not erase an old leak.
- It does not help if you approve a prompt you did not start.
- It does not replace a unique password on every site.
- It does not freeze your credit.
- It does not prove that a checker searched every database on earth.
How to turn MFA on without getting phished
The FTC’s consumer advice makes the same pairing: a strong unique password plus two-factor authentication, because even a good password can be stolen. If a page asks for your existing password and then immediately asks you to read a code to a “support agent” in chat, you are not turning MFA on. You are handing both factors to a stranger.
- Type the real website. Do not use a link from an unexpected “your account is at risk” email.
- Open Security or Sign-in settings.
- Choose the strongest method the service offers: passkey or security key first, authenticator app next, SMS last.
- Add a backup method you control, such as extra keys or backup codes stored in a password manager — not in a photo roll titled “codes.”
- Remove old phones and unknown devices.
- Repeat for email first. Email resets everything else.
Passkeys, in one paragraph
A passkey is a login credential stored on your device or in a manager and tied to the real website. When it is implemented well, a look-alike domain should not be able to replay it. That is why agencies keep pointing to phishing-resistant options for important accounts. You can still keep a password as a fallback on some services. Treat the passkey as the daily door and the password as the spare that must stay unique. After a leak, which accounts first? Order matters more than a perfect setup on a throwaway forum.
CISA’s short household list is still the right frame: unique passwords, MFA, updates, and caution with links. MFA is the piece that still works when an old password shows up in a file you cannot delete. Understanding what is multifactor authentication is useful. Turning it on for the mailbox that owns your other logins is the part that changes the risk.
- The email address that receives resets
- Apple, Google, or Microsoft accounts that hold the phone
- Banks, brokerages, payroll, and tax logins
- Password manager
- Shopping sites that store cards
- Social accounts that can impersonate you to family
Practical checklist
- Turn on MFA at the official site, not from an email link.
- Prefer passkeys, security keys, or an authenticator app over SMS.
- Store backup codes in a password manager.
- Deny login prompts you did not start.
- Unique password plus MFA on email and money accounts.
- Remove unknown devices after you enable it.
- Keep the phone and computer updated.
- Never read a code to someone who called you.
Frequently asked questions
Is two-factor authentication the same as MFA?
In consumer settings, people use the terms as synonyms. Both mean more than one proof. MFA is the broader name.
What if I lose the phone that gets the codes?
That is why backup methods matter. Use saved backup codes, a second key, or the provider’s official recovery process. Do not post the lost-phone story in a public thread with the account name attached.
Does MFA mean I can reuse passwords?
No. Reuse still spreads a leak from a weak site to a strong one if the second factor is missing or phished.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
