TechKnowSurge
ISC2 CC 3.2 CompTIA Tech+ 6.4 Cisco CCST Cybersecurity 1.3 NIST 800-53 IA-2 NIST 800-53 IA-5 NIST CSF PR.AA-03
VideoSecurityFree

IAM - Multi-Factor Authentication

Multi-factor authentication (MFA) requires users to verify their identity through more than one authentication factor, making it one of the most effective controls for preventing unauthorized account access. It represents a far greater security improvement than stronger passwords alone, which is why cybersecurity insurers increasingly mandate it as a coverage requirement.

Complete this video to capture a CTF flag worth 1 point.

About this video

Multi-factor authentication (MFA) is widely recognized as one of the highest-impact controls in access security, offering a substantially greater reduction in breach risk than improvements to password strength alone. The core principle is simple: instead of relying on a single credential to verify identity, MFA requires two or more independent factors, so that compromising one factor is not enough for an attacker to gain access. This is a primary reason cybersecurity insurers now commonly require MFA as a condition of coverage. Authentication factors are grouped into five categories. Something you know includes passwords, PINs, one-time passwords, and security questions. Something you have covers devices and credentials in a user's possession, such as smartphones receiving SMS or push notifications, hardware tokens, smart cards, certificates, authenticator apps, and badges. Something you are refers to biometric characteristics — fingerprint, palm print, retina scan, voice recognition, signature, or DNA. Somewhere you are uses location signals like IP address or geolocation to validate that a login attempt is coming from an expected region. Something you do captures behavioral patterns, such as restricting access to certain hours or requiring a specific sequence of actions. As MFA adoption matures, organizations are increasingly exploring passwordless authentication, which combines factors like biometrics and authenticator apps to verify identity without a traditional password. This approach can simplify the user experience while maintaining or even improving security, particularly when multiple strong factors are used together. Understanding how these factor types work and interact is foundational knowledge for anyone designing, evaluating, or managing identity and access controls in a modern IT environment.

What you'll learn

What's covered

Multi-Factor Authentication

Aligned to

ISC2 CC
3.2 Understand logical access controls
CompTIA Tech+
6.4 Compare and contrast authentication, authorization, accounting, and non-repudiation concepts
Cisco CCST Cybersecurity
1.3 Explain access management principles
NIST 800-53
IA-2 Identification and Authentication (Organizational Users)
IA-5 Authenticator Management
NIST CSF
PR.AA-03 Users, services, and hardware are authenticated.

Key terms

Authentication
The process of verifying the identity of a user, device, or system.
Multi-Factor Authentication
MFA
An authentication method that requires users to provide two or more verification factors to gain access.
Two-Factor Authentication
2FA
An authentication method that requires two distinct forms of verification before granting access.
Biometrics
Authentication methods that use unique physical or behavioral characteristics such as fingerprints or retinal scans.
One-time Password
OTP
A One-time Password is a code valid for only a single authentication session or transaction, generated by hardware tokens, authenticator apps, or SMS, providing stronger security than static passwords by eliminating the risk of credential replay attacks.
Passwordless Authentication
An authentication approach that verifies identity using two or more factors such as biometrics or possession-based tokens without requiring a traditional password.

Topics

Multi Factor Authentication Identity And Access Management Authentication Factors Credential Security Cybersecurity Insurance Iam

Transcript

What I've seen is it's very difficult to get a group of users all to create great passwords and practice good password management. And even if they did, there's things that threat agents can do to leverage credentials to get into systems. But most of that goes away when you use something like multifactor authentication. The improvement of going from an okay password to a great password is pretty small in comparison to when you incorporate something like multifactor authentication, which is one of the reasons why insurance agencies are requiring it if you're going to get cyber security insurance — because it's that big of an improvement.

From Single Factor to Multifactor

When you log into a system, you typically log in with a username and a password, and this is called single factor authentication. The single factor is this password that you enter. So if we wanted to do two factor authentication, that means that there's another factor involved. Two factor authentication is maybe at the same time we have to do a thumb print, so we would do a thumb print as our second factor.

Multifactor authentication is just anything besides a single factor authentication. That means there's multiple — two is multiple, three is multiple, four is multiple, whatever the case may be. It's just requiring more than one form of authentication.

The Categories of Factors

Factors can be broken down into five different categories: something you know, something you have, something you are, somewhere you are, or something you do. Some resources just list off these first three: something you know, something you have, and something you are.

Something you know would be something like a password, a PIN, a one-time password that you use once and then it goes away, a security word, or a security question.

Something you have would be something like — we're getting used to SMS messages, voice messages, email. We could also use certificates; we haven't gotten into certificates yet. But security keys, authenticator apps, tokens (both soft and hard tokens), and badges. So there are things that you have in your possession, whether it's on your computer or on your person, like a phone, that you can use to authenticate yourself.

Then there is something you are. This is things like a fingerprint, a palm print, voice, retina, signature, DNA — these are all examples of that.

Somewhere you are would be like an IP address or some sort of geolocation, and often geolocation is based off of IP address. But a geolocation would be like where you are at in this world. A good example of that would be, I get alerts if somebody logged into our email system from a foreign country, so that way we could figure out, are they on vacation or did somebody compromise the account?

And then something you do would be like you do something at a certain time, or there's a sequence of actions that you perform. A good example of this is maybe you're not able to log into your system unless during business hours.

Going Passwordless

Because of multifactor authentication, we actually have this concept of going passwordless. That means that maybe we don't need passwords in the future if we're using things like an authenticator app (something you have) and we're using something you are, like a fingerprint, or maybe it's a geolocation. Maybe we're using multiple items to authenticate you still, but without the need for a password. And so in some ways this can be very convenient, and maybe even more secure in some aspects.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →