multi-factor authentication (MFA)
a password is no longer enough
For many years, a strong password was the main defence against someone accessing your online accounts. Today, that is no longer the case.
Passwords can be stolen through scams, data breaches, malware or phishing emails. Even the strongest password can end up in the wrong hands.
Multi-Factor Authentication (MFA) adds a second layer of security. After entering your password, you must also prove that you are the legitimate owner of the account by providing something else that only you have.
This could be:
-
A code generated by an authentication app on your phone.
-
A prompt asking you to approve the sign-in.
-
A physical security key - this can be face-ID or Touch-ID and is often called a Passkey
-
A text message containing a one-time code (less secure, but still better than no MFA).
Because of this second factor, your password becomes much less valuable to a criminal. Even if someone discovers your password, they usually cannot access your account without that second approval.
For this reason, enabling MFA is one of the single biggest improvements you can make to your online security.
authentication Apps
Authentication apps generate a new six-digit code every 30 seconds. The codes are created on your device and continue to work even when your phone has no internet connection. These can be downloaded onyo your phone from the Apple App Store or the Google Play Store, depending on the type of phone you use.
The two most common apps are:
Microsoft Authenticator
Microsoft Authenticator works particularly well with Microsoft accounts and Microsoft 365. Instead of typing a code, you will often simply receive a notification asking you to approve the login with a single tap.
It can also store codes for many non-Microsoft websites and services.
Google Authenticator
Google Authenticator is simple, reliable and works with almost every online service that supports MFA. It displays time-based verification codes that you enter during login.
Although originally designed for Google accounts, it works just as well with Microsoft, Facebook, Dropbox, Xero, banking websites and hundreds of other services.
why text message MFA is not ideal
Many websites still offer verification codes by text message (SMS). While this is certainly better than having no MFA at all, it has several disadvantages.
If you're travelling overseas, your normal mobile number may not work, or you may be using a local SIM card that cannot receive messages sent to your home number.
Text messages can also be delayed, fail to arrive, or occasionally be intercepted through sophisticated attacks such as SIM swapping.
Authentication apps avoid these problems because they generate the codes directly on your phone without relying on your mobile network.
record your mfa information
Like passwords, your MFA setup should form part of your Technology Plan.
Consider recording:
-
Which accounts have MFA enabled.
-
Which authentication app you use.
-
Where your recovery or backup codes are stored.
-
Whether trusted family members know how to access your accounts if you become unable to manage them yourself.
Recovery codes are especially important. They allow you to regain access if you lose or replace your phone. Store them somewhere safe—ideally with the rest of your Technology Planning documents.
password managers and technology planning
Where possible, enable Multi-Factor Authentication on every important account, especially your:
-
Email (this is especially important as your email account can often be used to reset other password)
-
Microsoft account
-
Apple account
-
Google account
-
Banking
-
Password manager
A password protects your account.
Multi-Factor Authentication protects you even if your password is compromised.
need help setting up MFA?
I can help you choose the right authentication method, configure Microsoft or Google Authenticator, and make sure you don't get locked out of your accounts.
