Multi-factor Authentication
Definition
Requiring proof of two or more pieces of evidence in order to authenticate a user.
How it works
When logging into an account users present two or more credentials that fall into different categories: something you know (password or PIN), something you have (smart card or phone), or something you are (fingerprint).
Considerations
MFA configuration steps may vary across accounts and in some cases left up to users to activate and implement.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related ATT&CK Techniques:
These offensive techniques are determined related because of the way this defensive technique,, , and .
References
The following references were used to develop the Multi-factor Authentication knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)