Modern types of multi-factor authentication include SMS/Text confirmations, fingerprint scanners, facial recognition, mobile push approval, and IP/Location risk-based assessment. For a quick overview, read more.
What is multi-factor authentication?
Multi-factor Authentication (MFA) is an online cybersecurity measure that uses multiple pieces of information to allow the right people to access information and accounts, while making it very difficult for hackers and criminals to access accounts. For example, accessing your Gmail account used to only require a password, that was considered Single Point Authentication. However, now a sign-in from a new device requires a password AND a mobile phone text response, that is Two Factor Authentication (2FA). If three or more elements are required, that is considered Multi-Factor Authentication. Per Wikipedia:“Multi-factor authentication is an authentication method in which a [user] is granted access only after successfully presenting two or more pieces of evidence (or factors) to an authentication mechanism: knowledge (something the user and only the user knows), possession (something the user and only the user has), and inherence (something the user and only the user is).” – Wikipedia
What are the benefits and advantages of multi factor authentication?
The benefit of multi-factor authentication is increased security by adding additional requirements to gain access. Simply put, requiring two passwords would be more secure than just one password. However, requiring one password and one text confirmation would be even more secure. Extrapolating from there, requiring a password, a text confirmation, an approved IP address, and a biometric signature would be even more secure.What are the risks and disadvantages of multi factor authentication?
The basic risk and disadvantage of multi-factor authentication is “locking out” the correct user. If a salesforce tool is so complicated to access that the salespeople can’t use the tool, that’s a serious disadvantage. As such, the most effective MFA solution is one that blocks malicious hacks and data breaches, yet is simple and consistent for intended users to access.Is Multi-Factor Authentication effective?
Yes, multi-factor authentication is effective for the vast majority of businesses and users. A recent Forbes article suggests that MFA is “effective against 99% of account hacks.” And our clients see closer to 99.99% effectiveness. In the real world, the most effective MFA solution is one that delivers the utmost in security, while balancing safety with usability. Access must continue to be consistent and “easy” for the intended audience. We generally recommend these elements in an MFA solution: Username, Password, SMS/Text Confirmation, and IP/Location. For the most sensitive information, we implement biometric MFA solutions for our most demanding clients.Two Factor Authentication (2FA) vs Multi Factor Authentication (MFA)
Two-Factor Authentication is what we’re all familiar with: 1) Enter your username and password, 2) Reply to the text message you receive on your phone. Multi-Factor authentication adds another element, like IP address or location. For example, if you generally log-in to your account from an IP address in San Ramon, CA, then the system could flag attempts to log-in from Paris, France. Generally, an IP/Location flag might arise if there was a log-in in San Ramon, then a login attempt from Paris only a few minutes later. There are any number of MFA and adaptive MFA elements that can be used:- Password
- SMS/Text Confirmation
- Secondary Info (Security Question/Answer)
- Device Type
- Hardware Token
- Location/IP Address
- Biometrics/Fingerprint
What are the top multi factor authentication tools?
There are dozens of identity management tools and software vendors available. Here are some of our favorite IAM tools, with a note on why we like them, and when they’re right for a client:Okta Verify MFA
Okta is a flexible identity and access management tool that addresses the needs and budgets of small business and enterprise when it comes to Multifactor Authentication and Single Sign-On. We recommend it to companies offering customers an online log-in, i.e., online publishers and gaming.Idaptive MFA
A leader in cloud-based Multi-factor Authentication and Single Sign On, Idaptive is a flexible solution that’s easy to implement for small to large companies. We tend to recommend it to product based companies with a growing salesforce.Azure MFA (Microsoft)
Backed by Microsoft, Azure MFA is a robust enterprise solution, which requires extensive implementation experience and less day-to-day flexibility. We recommend Azure for established finance, healthcare, and global salesforces.What about MFA and biometrics?
Biometrics for multi-factor authentication generally refers to fingerprints and fingerprint scanners. It can also refer to facial recognition, voice recognition, and retina scanners. Recently, even the FBI has encouraged more companies to adopt biometric authentication. Currently, we feel the best biometric authentication option is a fingerprint scanner. (In some cases, these are also called no-password systems.)What is PAM multi-factor authentication?
Privileged Access Management (PAM) generally refers to an additional layer of security for accessing privileged account information, including the administrative dashboard and administrative layer of an MFA solution, offering access to “privileged” employees. This administrative component presents identity management challenges in itself. For example, how does the HR or sales team add a new employee to the salesforce? How does the CTO view and analyze security breach attempts and overall enterprise security? An effective PAM solution addresses these administrative and enterprise security needs.What is risk-based multi-factor authentication?
Risk-based multi-factor authentication, also known as adaptive MFA, uses dynamic variables to assess risk and reduce cybersecurity risks — without requiring the user to proactively input additional information. For example, a user may typically only be required to enter a Username and Password. However, a risk-based multi-factor authentication solution may further reduce hack threats by sensing the IP location of the user, the device, or any number of variables. Per the Okta website:“When a user attempts to sign in, a risk-based authentication solution analyzes factors such as their device, location, and network. It then calculates a risk rating based on these contextual elements, and can decide to allow the user access, prompt them to submit another authentication factor, or deny access altogether…” – Okta


