IT Glossary

Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) verifies identity with two or more factors. Learn how MFA works, its types, and how it fits IAM compliance with Corma.

May 25, 2026

Multi-Factor Authentication (MFA) is a security mechanism that requires a user to present two or more independent verification factors to gain access to an account or application. These factors combine something the user knows (a password), something they have (a device or token), and something they are (a biometric). MFA significantly reduces the risk of account takeover even when a password is stolen.

How MFA works

  • The user enters a primary credential, usually a password.
  • The system requests a second factor from a different category.
  • Common second factors include a one-time code, a push notification, a hardware security key, or a fingerprint.
  • Access is granted only when both factors validate.
  • Adaptive MFA can require extra factors based on risk signals such as a new device or unusual location.

Examples and use cases

A finance manager at a mid-market company logs into the expense platform with a password, then approves a push notification on a registered phone. If an attacker phishes the password, the missing device blocks the login. For compliance frameworks such as ISO 27001 and NIS2, MFA on privileged and sensitive accounts is effectively expected, not optional.

The governance challenge is consistency: MFA is only as strong as its weakest unprotected app. Tools that surface which accounts lack MFA turn a vague policy into a measurable control.

Related concepts

FAQ

What are the three factors in MFA?

Knowledge (a password or PIN), possession (a phone, token, or security key), and inherence (a biometric like a fingerprint or face scan).

Is two-factor authentication (2FA) the same as MFA?

2FA is a specific case of MFA that uses exactly two factors. MFA is the broader term and can require more than two.

Does MFA replace strong passwords?

No. MFA adds a layer, but weak or reused passwords still create risk, which is why passwordless methods are gaining ground.

Corma flags accounts and apps missing MFA across your stack and ties them back to compliance evidence. Explore Corma for security teams or request a demo.