Registration for Britannic's Annual Summit is now open!

Register Now!

*Updated 7 October 2026*

Passwords remain one of the most common ways organisations protect access to systems, applications and data, but on their own they are no longer enough.

Credentials can be stolen through phishing, reused across multiple accounts, exposed in data breaches or obtained through social engineering. Once an attacker has a valid username and password, their activity can initially look no different from a legitimate login. This is one of the reasons why identity has become such an important part of modern cyber security.

Multi-factor authentication, or MFA, adds another layer of verification before access is granted. Instead of relying on a password alone, users must prove their identity using two or more different authentication factors.

When implemented properly, MFA can significantly reduce the risk of account takeover, protect access to sensitive systems and give organisations greater control over how users authenticate. The challenge is making sure the technology is deployed in a way that strengthens security without creating unnecessary friction for employees.

What Is Multi-Factor Authentication?

Multi-factor authentication requires users to provide two or more different types of evidence before they are allowed to access a system or application.

These factors usually fall into three categories:

  • Something you know, such as a password or PIN

  • Something you have, such as a smartphone, hardware token or security key

  • Something you are, such as a fingerprint or facial recognition

The important distinction is that MFA combines different types of authentication. Entering two passwords would not normally count as true multi-factor authentication because both rely on the same type of factor.

A common example is a user entering their password and then approving the login through an authenticator application on a registered device. Even if the password has been compromised, the attacker would still need access to the second factor to complete the login.

This makes stolen credentials far less useful and adds a valuable layer of protection around important accounts and services.

Why Is Multi-Factor Authentication So Important?

MFA is designed to reduce the impact of compromised credentials.

Passwords can fail for many reasons, whether through phishing, reuse across multiple services, weak password choices or previous data breaches. Once an attacker obtains a valid username and password, their activity may initially look like a legitimate login, which is why relying on passwords alone creates unnecessary risk.

Adding a second form of verification makes those stolen credentials far less useful. Even if the password is correct, the attacker must still complete another authentication step before access is granted.

This is particularly important for:

  • Email and collaboration platforms

  • Cloud applications

  • Remote access

  • Administrator accounts

  • Financial systems

  • Customer data

  • Business-critical applications

  • Systems containing sensitive or regulated information

The National Cyber Security Centre recommends MFA as one of the most effective ways to protect important accounts from unauthorised access. In practical terms, the more valuable the account or system, the stronger the authentication around it should be.

Is All Multi-Factor Authentication Equally Secure?

Not all MFA methods provide the same level of protection, so organisations should avoid treating every form of authentication as interchangeable.

SMS Codes

SMS-based authentication sends a one-time code to the user's mobile phone.

It is generally more secure than relying on a password alone, but it can still be vulnerable to techniques such as SIM swapping, interception and social engineering. SMS may therefore be suitable where stronger methods are not practical, but it should not automatically be treated as the strongest option available.

Email Codes

Some services send verification codes to an email account.

This can provide an additional step, but the protection it offers depends heavily on how secure the email account itself is. If an attacker already controls the user's email, the additional factor may provide limited protection.

Authenticator Applications

Authenticator apps can generate time-based codes or send approval prompts to a registered device.

These are generally stronger than SMS because they are not dependent on the mobile network. They are also widely supported and relatively easy for users to adopt.

However, organisations should be aware of MFA fatigue. If users receive repeated authentication prompts, they may eventually approve one without checking whether they initiated the login.

Push Notifications

Push-based authentication allows a user to approve or reject a login request through an app.

This can create a convenient user experience, but it should be configured carefully. Number matching and contextual information can make push authentication more secure by asking users to confirm a specific number or verify details about the login.

Hardware Security Keys

Physical security keys provide a strong form of authentication and are particularly suitable for administrators, privileged users and other high-risk accounts.

Modern phishing-resistant security keys can verify both the user and the legitimate service they are connecting to, making them much more difficult to defeat through traditional phishing attacks.

Biometrics

Biometric authentication uses characteristics such as fingerprints or facial recognition to verify identity.

This can provide a convenient and secure experience when used alongside a trusted device. However, biometrics are usually most effective as part of a wider authentication process rather than being treated as the only control.

What Does Phishing-Resistant Multi-Factor Authentication Mean?

Traditional MFA can still be defeated if an attacker convinces a user to approve a fraudulent login or enter their authentication code into a fake website.

Phishing-resistant MFA is designed to reduce that risk.

Technologies based on standards such as FIDO2 and WebAuthn use cryptographic authentication rather than codes that can be copied or intercepted. This makes them much harder to bypass using conventional phishing techniques.

Phishing-resistant MFA is particularly valuable for:

  • Privileged administrators

  • IT teams

  • Senior leadership

  • Finance teams

  • Users with access to sensitive data

  • Accounts that can make system-wide changes

For organisations reviewing their MFA strategy, the question should therefore not simply be whether MFA is enabled. It should also be whether the authentication method being used is appropriate for the level of risk.

Where Should Multi-Factor Authentication Be Used?

MFA is often associated with remote access, but its role is much broader.

It should be considered anywhere compromised credentials could expose important systems, applications or information.

Priority areas usually include administrator and privileged accounts, email services, cloud platforms, remote access, financial systems and business applications that hold sensitive data.

A risk-based approach can help organisations decide where to begin. Rather than attempting to protect every account at once, IT teams can focus first on the users and systems where compromise would have the greatest impact.

This often includes:

  • Administrators

  • Senior leadership

  • Finance

  • HR

  • IT support

  • Remote workers

  • Users with access to regulated data

  • High-value cloud applications

Once these areas are protected, MFA can be extended more widely across the organisation.

What Are The Best Practices For Implementing Multi-Factor Authentication?

A successful MFA strategy is not simply about enabling a second factor and considering the job complete. The way authentication is introduced, managed and reviewed has a significant effect on both security and user experience.

Start With The Highest-Risk Accounts

Trying to introduce MFA everywhere at once can make deployment more difficult than it needs to be.

A risk-based approach usually begins with the accounts that could create the greatest impact if compromised. This often includes administrators, senior leaders, finance teams, IT support and users with access to sensitive systems.

Once those users are protected, the organisation can extend MFA more broadly.

Choose The Right Authentication Method

The strongest authentication option is not always required for every user, but the method should match the risk.

A standard business user may not need the same level of protection as a systems administrator with access to critical infrastructure.

Higher-risk users may justify phishing-resistant security keys, while other users may be adequately protected through an authenticator application.

This helps organisations strengthen security without creating unnecessary inconvenience.

Avoid Relying On SMS Where Stronger Options Are Available

SMS remains better than password-only access, but stronger methods should be preferred for important systems where practical.

Authenticator applications, hardware tokens and phishing-resistant methods can provide better protection against interception and social engineering.

This does not mean every organisation needs to remove SMS immediately. It means understanding where it is being used and deciding whether stronger alternatives are justified.

Protect The Enrolment And Reset Process

One area that is often overlooked is how users enrol or replace their second factor.

If an attacker can easily register a new authentication device after compromising an account, the MFA control may be bypassed.

Organisations should therefore have clear processes for:

  • Registering new devices

  • Replacing lost phones

  • Resetting authentication factors

  • Verifying user identity during support requests

  • Removing old authentication methods

Helpdesk teams should also be aware that attackers may try to impersonate legitimate users in order to persuade support staff to reset MFA.

Use Number Matching Where Available

Simple push notifications can create problems if users receive repeated login requests.

Number matching can improve the process by requiring users to enter or confirm a number shown on the service they are trying to access.

This makes it harder to approve a fraudulent login by accident and gives users more context about the authentication request.

Combine MFA With Single Sign-On

Security and usability do not have to work against each other.

Single sign-on can allow users to authenticate once and securely access multiple approved applications. When combined with strong MFA, this can reduce the number of passwords users need to remember while giving IT teams more centralised control over access.

It can also make it easier to remove access when an employee leaves or changes role.

Use Risk-Based Authentication

Not every login carries the same level of risk.

Adaptive or risk-based authentication can take into account factors such as:

  • User location

  • Device

  • Time of access

  • Login behaviour

  • Network

  • Sensitivity of the application

A user logging in from a recognised corporate device during normal working hours may be treated differently from the same account attempting to access a sensitive application from an unfamiliar location.

This allows organisations to strengthen authentication where it matters most without adding unnecessary friction to every login.

Why Does MFA Need A Secure Recovery Process?

MFA needs a secure recovery process for situations where users lose access to their authentication device.

Without one, employees can become locked out of critical systems. If the recovery process is too relaxed, however, attackers may use it to bypass the authentication controls altogether.

Recovery should therefore balance security with practicality.

Organisations should define:

  • How identity will be verified

  • Who can approve an MFA reset

  • Which temporary access methods are permitted

  • How lost devices are removed

  • How authentication changes are logged

  • How suspicious reset requests are escalated

The reset process should receive the same level of scrutiny as the authentication technology itself.

What Are The Most Common Multi-Factor Authentication Mistakes?

Many MFA weaknesses are caused by poor implementation rather than the technology itself.

One of the most common mistakes is protecting only a small number of accounts while leaving other users with access to the same sensitive systems on password-only authentication. Attackers will naturally look for the weakest route into the environment.

Another mistake is treating every user in exactly the same way. Administrators and privileged users should usually have stronger controls than lower-risk accounts, particularly where they can make system-wide changes.

Other common issues include:

  • Insecure MFA reset processes

  • Old devices remaining registered

  • Legacy applications that do not support modern authentication

  • Excessive reliance on SMS

  • Push notifications without number matching

  • Users approving unexpected authentication requests

  • Exceptions that are never reviewed

  • Poor visibility of failed or unusual authentication attempts

The goal should be to understand where gaps remain rather than assuming that enabling MFA automatically removes credential-related risk.

How Does Multi-Factor Authentication Fit Into A Wider Security Strategy?

MFA is one of the most valuable identity security controls an organisation can introduce, but it should not operate in isolation.

It works best alongside sensible access policies, strong identity management, secure remote access and clear controls around privileged accounts.

MFA can confirm that a user has access to an approved authentication factor, but it does not determine whether that user should have access to every application or system.

This is why organisations increasingly combine MFA with:

  • Least-privilege access

  • Single sign-on

  • Central identity management

  • Conditional access

  • Risk-based authentication

  • Zero Trust principles

The objective is not to introduce more authentication steps. It is to make access decisions more intelligently and apply stronger controls where the risk is highest.

A Practical MFA Strategy

For organisations reviewing their current approach, a useful strategy can be built around five steps.

  1. Identify - Understand which systems, applications and accounts need stronger authentication. Start with the areas where compromised credentials would create the greatest impact.
  2. Prioritise - Protect administrators, high-risk users and business-critical services first.
  3. Strengthen - Move towards stronger authentication methods where appropriate, particularly for privileged access.
  4. Simplify - Use central identity management and single sign-on where possible to improve both control and user experience.
  5. Review - Monitor authentication activity, remove obsolete methods and regularly reassess whether the controls still match the risk. This turns MFA into an ongoing security control rather than a one-off implementation project.

MFA Implementation Checklist

Before considering an MFA deployment complete, organisations should be able to answer the following questions:

  • Is MFA enabled on all privileged accounts?

  • Is MFA required for remote access?

  • Are important cloud applications protected?

  • Are email accounts covered?

  • Are stronger authentication methods used for higher-risk users?

  • Is SMS being replaced where stronger options are practical?

  • Are MFA enrolment and reset processes secure?

  • Are old devices and tokens removed?

  • Are authentication logs monitored?

  • Are users trained to recognise suspicious MFA prompts?

  • Are exceptions documented and regularly reviewed?

  • Are legacy systems creating gaps in MFA coverage?

  • Is there a clear recovery process for lost devices?

  • Does the organisation know which applications still rely on password-only access?

Any unanswered question is worth investigating because MFA is only as strong as the gaps around it.

How Can Britannic Support MFA?

Multi-factor authentication is most effective when it is integrated into the wider security environment rather than introduced as an isolated tool.

Britannic Technologies helps organisations assess identity and authentication requirements, design appropriate MFA policies and integrate authentication with wider networking and security infrastructure.

The company works with Fortinet technologies including FortiAuthenticator, which can support multi-factor authentication, identity management and single sign-on across business environments.

This allows organisations to take a more joined-up approach to authentication, access and network security, while avoiding unnecessary complexity for users and IT teams.

Britannic Technologies can also support wider security reviews where MFA forms part of a broader requirement around secure remote access, network security, identity management or managed services.

Strengthen Access Before Credentials Are Compromised

Passwords are unlikely to disappear overnight, but organisations no longer need to rely on them alone.

A well-designed MFA strategy makes stolen credentials much less useful and provides greater control over access to important systems and data. The most effective approach is not simply switching MFA on everywhere and considering the work complete. It is understanding which accounts carry the greatest risk, choosing suitable authentication methods, protecting enrolment and recovery processes, and reviewing the strategy as the organisation changes.

Review Your Authentication Strategy With Britannic