Multi-Factor Authentication (MFA) Explained

Multi-factor authentication (MFA) requires a second proof of identity beyond a password – a code from an app, a prompt on your phone, or a hardware key. It means a stolen password alone is not enough to get into an account, and it stops the large majority of account-takeover attacks.

The methods, strongest first

  • Hardware keys (FIDO2) – phishing-resistant, best for admins and high-value accounts
  • Authenticator app with number matching – strong, the practical default
  • Push approval – convenient but vulnerable to ‘MFA fatigue’ if a user taps approve without thinking
  • SMS codes – better than nothing, but interceptable; use only where nothing else is supported

Where to turn it on

  • Email – first
  • Remote access and VPN
  • Microsoft 365 / Google Workspace admin accounts
  • Banking, payroll, accounting
  • Any system holding customer or financial data
  • Ideally everything – conditional access can reduce the prompts on trusted devices

Common objections

  • “It slows staff down” – seconds a day; conditional access removes most prompts on known devices
  • “We’re too small to be targeted” – attacks are automated and untargeted; small businesses are hit constantly
  • “What if someone loses their phone?” – set up backup methods and an admin recovery process in advance

We roll out MFA across your accounts with the right method per account type – part of our cybersecurity service.

Related security guides

Want this handled? See our cybersecurity service or talk to our Edmonton team.

Frequently asked questions

Is MFA really that effective?

Yes – it blocks the overwhelming majority of automated account-takeover attempts, which almost all rely on stolen or guessed passwords. It is the highest-value security control per dollar.

Which MFA method should we use?

An authenticator app with number matching for most users; hardware keys for administrators and anyone with access to money or sensitive data. Avoid SMS where you can.

What is MFA fatigue?

An attacker with a stolen password triggers repeated push prompts hoping the user eventually taps approve. Number matching and login context defeat it.

How does Scandifix help?

We enable MFA across all accounts, choose the right method per account, set up conditional access to reduce prompts, and configure recovery so a lost phone is not a lockout.