glossary

What is multi-factor authentication (MFA)?

A cited second opinion for choosing your next tech certification or training path.

Build my personalized career plan

Multi-factor authentication (MFA) requires two or more distinct types of proof to confirm identity — such as something you know, something you have, or something you are — rather than a password alone.

What it means

NIST defines MFA as authentication using two or more factors: knowledge (a password or PIN), possession (a token or device), or inherence (a biometric). Requiring more than one factor makes stolen passwords far less useful to an attacker. MFA is a baseline control across identity, cloud, and security roles.

Core source records

This table lists the page’s core content records and when they were checked. Claim-specific citations appear beside the relevant text and may not be repeated here.

IDSupportsSourceChecked
CIT-01Definition source for What is multi-factor authentication (MFA)?National Institute of Standards and Technology — NIST CSRC Glossary2026-06-15

Ready to turn this decision into a plan?

RoleMath planner