Skip to content
Glossary
Definition

Multi-factor authentication (MFA)

Multi-factor authentication (MFA) is a sign-in check that asks for a second proof of identity, such as an authenticator app or hardware key, so a stolen password isn't enough to open a business account.

Multi-factor authentication (MFA) is a sign-in control that asks for two different proofs of identity before an account opens. A password is something you know. The second factor is something you have, such as an authenticator app or hardware key, or something you are, such as a fingerprint. A stolen password then isn't enough on its own. UK firms usually apply it first to Microsoft 365, remote access and finance.

Staff enter a password, then confirm it in an authenticator app or with a security key. Microsoft 365 usually comes first, then VPN, HR and finance tools. Apps that ask you to type a matching number beat text-message codes, which can be stolen in a SIM swap. Hardware keys fit payroll, banking and admin accounts. Operations owns who is covered and what happens when a phone is lost.

It fails when only some systems are covered. Staff then reuse a password on an unprotected app, or keep a shared mailbox nobody protects. SMS codes, prompts that people tap without reading, and recovery that falls back to the same email all weaken it. Admin accounts left without MFA are a common gap. So are service accounts that cannot use an app but still hold high privileges. A workable policy names every system in scope and bans SMS for anyone with admin rights. Saved-device exceptions should expire after a set period.

When it matters

  • Staff sign in to Microsoft 365, payroll or finance from home.
  • Applying for Cyber Essentials or a client security questionnaire.
  • Admin accounts, shared mailboxes or contractor access still use a password only.
  • Customers, insurers or regulators ask how you protect cloud accounts.

Multi-factor authentication (MFA): common questions

What is multi-factor authentication (MFA)?

Multi-factor authentication is a sign-in check that asks for two different proofs of identity before an account opens. The first is usually a password. The second is typically an authenticator app, a hardware key or a biometric on a company device. The point is that a leaked or guessed password cannot open the account on its own. Businesses apply it to email, cloud apps, remote access and finance systems for that reason.

What's the difference between MFA and 2FA?

Two-factor authentication (2FA) is MFA with exactly two factors. MFA is the broader term and can require two or more. In most businesses they mean the same thing: a password plus a second check. The useful distinction is the type of second factor. A text-message code is still 2FA, but it's weaker than an authenticator app or a hardware key. When a supplier says they "have MFA", ask which method staff actually use, and which accounts it covers.

Is MFA required for Cyber Essentials?

Yes. Cyber Essentials requires multi-factor authentication on cloud services that support it. For most UK firms that means Microsoft 365, including admin accounts. A password-only cloud mailbox won't meet the current scheme. Passing the assessment still leaves operational choices, including how contractors sign in and how shared mailboxes are handled. An authenticator app or hardware key is the sounder choice for anyone with admin rights.

Ready to talk?

Book a free, no-obligation discovery call. We'll learn about your business and show you exactly how Wanzo can help — with a bespoke proposal within 48 hours.

No commitment. No sales pressure. Just honest advice.