Security

Turn on multi-factor authentication right now

Multi-factor authentication adds a second check beyond your password. It's one of the easiest, most effective ways to keep accounts secure. Turn it on everywhere.

January 4, 2024

Multi-factor authentication (MFA) is one of the easiest and most effective ways to protect your accounts, and you should turn it on everywhere it's available. Here's what it is, why it works, and how to manage it across all the services you use.

What is MFA?

Multi-factor authentication (also called 2-factor authentication or 2-step verification) adds security layers on top of your username and password to protect your accounts and devices from unauthorized access. With MFA enforced, you get in only when a second method — usually a one-time password or a login confirmation from a device you have — validates your identity.

As work-from-anywhere becomes the norm, access to confidential information is no longer protected by physical access to an office or a desktop computer. With a traditional username and password alone, someone could log into your company's Dropbox account from anywhere in the world if your password has been compromised. MFA is one of the easiest layers to add for preventing that kind of unauthorized access and improving your digital security. You really should be using MFA everywhere it's available.

You probably already use MFA

You may already use MFA on some of your accounts. For example:

  • When you log into your bank's online portal with your username and password, a 6-digit code is sent to your mobile number.
  • Your company uses Microsoft 365 for email, and when you sign in you get a push notification from the Microsoft Authenticator app on your phone.
  • Your company lets you work from home, but when you do you need to keep a USB dongle attached to your computer to access your company email.
  • You get a new MacBook, and when you sign in to your Apple ID you get a push notification or authentication code on another Apple device you own (an iPhone or iPad) that is already signed in to the same Apple ID.

Something you know plus something you have

In all four cases, your username and password together are not enough. You also need something you have physical access to — your phone, a USB dongle, another Apple device — to get in. That's why MFA is often described as something you know (your password) plus something you have (your phone). Requiring both makes it much more likely that the person accessing your account is really you.

Verification codes and push notifications are time-sensitive. The 6-digit code your bank sends is probably valid for no more than five minutes. The 6-digit codes in an authenticator app are valid for only 30 seconds. Push notifications are valid for only 60 seconds. These time limits reduce the chances that someone can intercept a code with enough time to impersonate you.

Biometric authentication (fingerprint or facial recognition) can also serve as an additional method. In some cases, administrators can set up trust rules for specific devices, IP addresses, or geographic regions to reduce the number of devices that could gain access to confidential information.

Centralized MFA

Managing MFA across the many accounts you use can be a hassle. Each one might use a different method on a different device with a different time frame, which gets confusing. Worse, even if you carefully set up MFA for some accounts, you might forget another and open a vulnerability in your systems.

Identity and access management (IAM) solutions tackle this by rolling authentication for many services into a single platform. With IAM properly configured and maintained, you use a single sign-on (SSO) portal with strong security requirements — including enforced MFA — and from that portal reach the other systems you need.

Macktez Identity Management

To protect our clients' systems with a centralized IAM solution, our Identity Management subscription manages verification for online services and local computer accounts so users have a unified identity for authentication. We always enforce MFA for this service, and we can add conditions for clients with greater security needs or lower tolerance for risk. With Identity Management, tightening security for one service automatically tightens it for everything, keeping a consistent security profile across your entire organization.

Work With Us

Have a project like this on the horizon?

If something here maps to what your organization is facing, let's talk it through — no pitch deck, just a senior technical perspective on your situation.