What is Two-factor authentication (2FA)?

Also known as: MFA, multi-factor authentication

Two-factor authentication (2FA) means logging in requires a second proof besides the password: a code from an app, a security key or a fingerprint. A stolen password alone is no longer enough.

Security keys and authenticator apps are the strongest; SMS codes are weaker but still far better than nothing. 2FA can also be phished, so a code should never be shared with anyone.

How to spot it

  • An approval prompt when you are not logging in
  • Someone asks you for a code by phone or message

What to do

  • Turn on 2FA for every work and financial account
  • Reject unexpected prompts and report them to IT

Related courses

Terms on this topic

More topics

← Cybersecurity glossary

Start with your team's risk baseline

15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.