GlossarySecurity & compliance

MFA (multi-factor authentication)

Multi-factor authentication (MFA) requires a second proof of identity beyond a password, such as a code from an app or a hardware key, and it defeats most attacks that rely on stolen passwords.

  • Security & compliance
  • Updated
  • Written by the Telxpress advisory team

01 In depth

What it is, why it matters and what to ask a vendor

NIST's digital identity guidelines (SP 800-63B) describe authentication factors as something you know, something you have and something you are; MFA combines at least two. Authenticator apps, hardware security keys and device-based prompts are stronger than codes sent by text message, which can be intercepted or redirected.

For a growing business MFA is the single control most often required by the rules that already apply to it: the FTC Safeguards Rule names it, cyber insurers ask about it, and HIPAA and PCI DSS expect it for remote and administrative access. It belongs on email, the phone system portal, the firewall, remote access, the CRM, banking and every admin account, including the vendors' accounts into your systems.

Ask each vendor whether MFA is available on every login to their product, whether it can be enforced for all users rather than offered, which methods are supported, and how a lost phone or key is recovered without opening a hole. Ask your IT partner to roll it out in an order that starts with email and administrator accounts.

03 At Telxpress

Where this shows up at Telxpress

The pages and articles where this term does real work: what we advise, build and support.

04 Sources

Public references

The standard or law this definition rests on, as published by its owner. Fetched and checked on the review date above.

Next step

Want This Applied to Your Business?

Book a free 30-minute AI readiness consultation. You'll leave with three AI opportunities specific to your business, whether you work with us or not.

Or call 24/7: (949) 861-4500

Last reviewed: . Published by Telxpress, Irvine, CA.