IT Glossary
Multi-Factor Authentication (MFA) verifies identity with two or more factors. Learn how MFA works, its types, and how it fits IAM compliance with Corma.
May 25, 2026
Multi-Factor Authentication (MFA) is a security mechanism that requires a user to present two or more independent verification factors to gain access to an account or application. These factors combine something the user knows (a password), something they have (a device or token), and something they are (a biometric). MFA significantly reduces the risk of account takeover even when a password is stolen.
A finance manager at a mid-market company logs into the expense platform with a password, then approves a push notification on a registered phone. If an attacker phishes the password, the missing device blocks the login. For compliance frameworks such as ISO 27001 and NIS2, MFA on privileged and sensitive accounts is effectively expected, not optional.
The governance challenge is consistency: MFA is only as strong as its weakest unprotected app. Tools that surface which accounts lack MFA turn a vague policy into a measurable control.
Knowledge (a password or PIN), possession (a phone, token, or security key), and inherence (a biometric like a fingerprint or face scan).
2FA is a specific case of MFA that uses exactly two factors. MFA is the broader term and can require more than two.
No. MFA adds a layer, but weak or reused passwords still create risk, which is why passwordless methods are gaining ground.
Corma flags accounts and apps missing MFA across your stack and ties them back to compliance evidence. Explore Corma for security teams or request a demo.