Understanding MFA
There are few technical features that protect your accounts more than using MFA. With MFA, it is not enough to know a username and a password; you are also challenged to prove who you are using another authentication factor. With MFA, you generally need to be able to log in with the following:
- Something you are, such as your user account name or a biometric attribute
- Something you know, such as a password
- Something you have, such as an additional authentication factor (smartcard, smartphone app, or security key)
Given the fact that an MFA challenge is only triggered following a successful login attempt, it is still reliant on passphrases that are not easy to guess. In other words, if an MFA challenge is triggered, the respective username/password combination has already been successfully validated (refer to the following screenshot for reference):