Multi-factor authentication (MFA) requires two or more distinct types of proof to confirm identity — such as something you know, something you have, or something you are — rather than a password alone.
What it means
NIST defines MFA as authentication using two or more factors: knowledge (a password or PIN), possession (a token or device), or inherence (a biometric). Requiring more than one factor makes stolen passwords far less useful to an attacker. MFA is a baseline control across identity, cloud, and security roles.