{"id":71777,"date":"2024-06-20T11:26:31","date_gmt":"2024-06-20T11:26:31","guid":{"rendered":"https:\/\/logmeonce.com\/resources\/2023\/08\/13\/examples-of-mfa\/"},"modified":"2026-07-29T01:00:24","modified_gmt":"2026-07-29T01:00:24","slug":"examples-of-mfa","status":"publish","type":"post","link":"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/","title":{"rendered":"Examples of MFA: Practical Guide for Individuals &amp; IT Teams"},"content":{"rendered":"<div class=\"336cb5b64765e27a1a6c1bb71b941f1a\" data-index=\"1\" style=\"float: none; margin:10px 0 10px 0; text-align:center;\">\n<script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-4830628043307652\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<!-- above content -->\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block\"\r\n     data-ad-client=\"ca-pub-4830628043307652\"\r\n     data-ad-slot=\"5864845439\"\r\n     data-ad-format=\"auto\"\r\n     data-full-width-responsive=\"true\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script>\n<\/div>\n<\/p>\n<hr>\n<blockquote>\n<p><strong>TL;DR:<\/strong><\/p>\n<ul>\n<li>Multi-factor authentication combines credentials from different categories, enhancing security beyond passwords alone.<\/li>\n<li>Organizations should prioritize phishing-resistant methods like hardware keys and passkeys, especially for high-risk accounts.<\/li>\n<\/ul>\n<\/blockquote>\n<hr>\n<p>The most common examples of MFA are: password + SMS one-time code, password + TOTP authenticator app, password + push notification, password + hardware security key (FIDO2\/YubiKey), password + biometric (fingerprint or face), smart card\/PIV + PIN, PKI certificate + PIN, and passwordless passkey (FIDO2 alone). Each pairs a primary credential with a second or third factor from a different category.<\/p>\n<p>Here is the quick-reference list:<\/p>\n<ul>\n<li><strong>Password + SMS OTP<\/strong> \u2014 a one-time code texted to your phone<\/li>\n<li><strong>Password + TOTP app<\/strong> \u2014 a 6-digit code from Google Authenticator, Authy, or Microsoft Authenticator, refreshing every 30 seconds<\/li>\n<li><strong>Password + push notification<\/strong> \u2014 a tap-to-approve prompt sent to a registered mobile app<\/li>\n<li><strong>Password + hardware security key<\/strong> \u2014 a physical FIDO2 device such as a YubiKey plugged into USB or tapped over NFC<\/li>\n<li><strong>Password + biometric<\/strong> \u2014 fingerprint or face scan on a trusted device<\/li>\n<li><strong>Smart card \/ PIV + PIN<\/strong> \u2014 common in federal government and healthcare<\/li>\n<li><strong>PKI certificate + PIN<\/strong> \u2014 certificate stored on a device or token, verified cryptographically<\/li>\n<li><strong>Passwordless passkey (FIDO2\/WebAuthn)<\/strong> \u2014 replaces the password entirely; the device authenticates via biometric or PIN bound to a cryptographic key<\/li>\n<li><strong>Email OTP<\/strong> \u2014 a code sent to a registered email address (low-assurance fallback)<\/li>\n<li><strong>Backup codes<\/strong> \u2014 static one-time codes generated at enrollment for account recovery<\/li>\n<\/ul>\n<p>NIST SP 800-63B defines MFA as requiring two or more distinct factors from separate categories. Logmeonce supports the full range above, including passwordless options.<\/p>\n<p><strong>Pro Tip:<\/strong> <em>Start with TOTP or a hardware key for any admin account. SMS is better than nothing, but it is the weakest option on this list and should be treated as a fallback, not a primary second factor.<\/em><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/csuxjmfbwmkxiegfpljm.supabase.co\/storage\/v1\/object\/public\/blog-images\/organization-6456\/1785096377282_Close-up-hands-using-authenticator-app-smartphone.jpeg\" alt=\"Close-up hands using authenticator app smartphone\" title=\"\"><\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_77 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#How_authentication_factor_categories_map_to_real_MFA_examples\" >How authentication factor categories map to real MFA examples<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Deep_dive_how_each_common_MFA_example_works\" >Deep dive: how each common MFA example works<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#SMS_one-time_password_OTP\" >SMS one-time password (OTP)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#TOTP_authenticator_apps\" >TOTP authenticator apps<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Push_notifications\" >Push notifications<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Hardware_security_keys_YubiKey_FIDO2WebAuthn\" >Hardware security keys (YubiKey, FIDO2\/WebAuthn)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Biometrics_fingerprint_face_recognition\" >Biometrics (fingerprint, face recognition)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Smart_cards_and_PIV_certificates\" >Smart cards and PIV certificates<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#PKI_certificates_device_or_software-based\" >PKI certificates (device or software-based)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Passwordless_passkeys_FIDO2WebAuthn\" >Passwordless passkeys (FIDO2\/WebAuthn)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Email_OTP_and_backup_codes\" >Email OTP and backup codes<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Security_best_practices_and_common_pitfalls_to_avoid\" >Security best practices and common pitfalls to avoid<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#How_to_choose_the_right_MFA_method_for_your_situation\" >How to choose the right MFA method for your situation<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#How_Logmeonce_approaches_MFA_and_passwordless_authentication\" >How Logmeonce approaches MFA and passwordless authentication<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Key_Takeaways\" >Key Takeaways<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#The_trade-off_nobody_talks_about_enough\" >The trade-off nobody talks about enough<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Logmeonce_makes_phishing-resistant_MFA_practical\" >Logmeonce makes phishing-resistant MFA practical<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/logmeonce.com\/resources\/examples-of-mfa\/#Authoritative_sources_and_further_reading\" >Authoritative sources and further reading<\/a><\/li><\/ul><\/nav><\/div>\n<h2 id=\"how-authentication-factor-categories-map-to-real-mfa-examples\"><span class=\"ez-toc-section\" id=\"How_authentication_factor_categories_map_to_real_MFA_examples\"><\/span>How authentication factor categories map to real MFA examples<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><img decoding=\"async\" src=\"https:\/\/csuxjmfbwmkxiegfpljm.supabase.co\/storage\/v1\/object\/public\/blog-images\/organization-6456\/1785096380221_Woman-authenticating-laptop-with-fingerprint-sensor.jpeg\" alt=\"Woman authenticating laptop with fingerprint sensor\" title=\"\"><\/p>\n<p>Every MFA method draws from at least two of four factor categories. Understanding the categories tells you immediately whether a combination actually qualifies as MFA or just two instances of the same factor type.<\/p>\n<p><strong>Something you know<\/strong> \u2014 a secret only the user holds:<\/p>\n<ul>\n<li>Password or passphrase<\/li>\n<li>PIN<\/li>\n<li>Security question answer (low assurance; avoid as a sole second factor)<\/li>\n<\/ul>\n<p><strong>Something you have<\/strong> \u2014 a physical or digital object in the user\u2019s possession:<\/p>\n<ul>\n<li>TOTP authenticator app (Google Authenticator, Authy, Microsoft Authenticator)<\/li>\n<li>Hardware security key (YubiKey, FIDO2 token)<\/li>\n<li>Smart card \/ PIV card<\/li>\n<li>Phone receiving an SMS OTP or push notification<\/li>\n<li>PKI certificate stored on a device<\/li>\n<\/ul>\n<p><strong>Something you are<\/strong> \u2014 a biometric characteristic:<\/p>\n<ul>\n<li>Fingerprint scan<\/li>\n<li>Face recognition (Face ID, Windows Hello)<\/li>\n<li>Voice recognition (less common; higher error rates)<\/li>\n<\/ul>\n<p><strong>Something you do \/ contextual signals<\/strong> \u2014 behavioral and location factors used in adaptive MFA to adjust authentication requirements dynamically:<\/p>\n<ul>\n<li>Typing cadence and mouse movement patterns<\/li>\n<li>GPS location or IP geolocation<\/li>\n<li>Device posture and health signals<\/li>\n<\/ul>\n<p>NIST SP 800-63B and Microsoft guidance both treat the first three categories as the primary factor types for assurance-level calculations. Behavioral and location signals typically serve as risk signals that trigger step-up authentication rather than as standalone factors.<\/p>\n<h2 id=\"deep-dive-how-each-common-mfa-example-works\"><span class=\"ez-toc-section\" id=\"Deep_dive_how_each_common_MFA_example_works\"><\/span>Deep dive: how each common MFA example works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3 id=\"sms-one-time-password-otp\"><span class=\"ez-toc-section\" id=\"SMS_one-time_password_OTP\"><\/span>SMS one-time password (OTP)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>When you log in, the service sends a 4\u20138 digit code to your registered phone number via text. You enter it within a short window, usually 5\u201310 minutes. The code is generated server-side and delivered over the public telephone network.<\/p>\n<p><strong>Pros and cons:<\/strong><\/p>\n<ul>\n<li>\u2705 No app required; works on any phone<\/li>\n<li>\u2705 Fast to deploy for consumer-facing services<\/li>\n<li>\u274c Vulnerable to SIM-swapping, SS7 interception, and real-time phishing proxies<\/li>\n<li>\u274c Fails when the user has no cell signal<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/phishing-resistant-multi-factor-authentication-mfa-success-story-usdas-fast-identity-online-fido\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">CISA explicitly flags<\/a> SMS OTP as susceptible to MFA bypass attacks and recommends moving to phishing-resistant alternatives where feasible. Deployment cost is near zero, but the security ceiling is low. Best for: consumer accounts where any MFA is better than none, or as a fallback only.<\/p>\n<h3 id=\"totp-authenticator-apps\"><span class=\"ez-toc-section\" id=\"TOTP_authenticator_apps\"><\/span>TOTP authenticator apps<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Apps like Google Authenticator, Authy, and Microsoft Authenticator generate <a href=\"https:\/\/support.microsoft.com\/en-us\/security\/what-is-multifactor-authentication\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">time-based one-time passwords<\/a> that rotate every 30 seconds using a shared secret established at enrollment. The code never travels over the network during login \u2014 only the user\u2019s input does.<\/p>\n<p><strong>Pros and cons:<\/strong><\/p>\n<ul>\n<li>\u2705 Works offline; no cell signal needed<\/li>\n<li>\u2705 Much harder to intercept than SMS<\/li>\n<li>\u2705 Free for users; low cost to deploy<\/li>\n<li>\u274c Still phishable via real-time proxy attacks (attacker relays the code before it expires)<\/li>\n<li>\u274c Device loss requires recovery flow<\/li>\n<\/ul>\n<p>Authy adds encrypted cloud backup of TOTP seeds, which simplifies device migration but introduces a cloud dependency. Google Authenticator added encrypted backup in 2023. Microsoft Authenticator ties backup to a Microsoft account. Deployment complexity is low: scan a QR code at enrollment, done. Best for: individuals, SMBs, and most enterprise workloads that cannot yet deploy hardware keys.<\/p>\n<h3 id=\"push-notifications\"><span class=\"ez-toc-section\" id=\"Push_notifications\"><\/span>Push notifications<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The authentication server sends an approve\/deny prompt to the user\u2019s registered mobile app. The user taps \u201cApprove\u201d and the session proceeds. No code to type.<\/p>\n<p><strong>Pros and cons:<\/strong><\/p>\n<ul>\n<li>\u2705 Lowest friction of any second factor<\/li>\n<li>\u2705 Displays context (location, app name) so users can spot anomalies<\/li>\n<li>\u274c Vulnerable to push fatigue (MFA bombing): attackers send repeated prompts hoping the user taps approve out of frustration<\/li>\n<li>\u274c Requires internet connectivity and a smartphone<\/li>\n<\/ul>\n<p>Number-matching and additional context (showing the login location) significantly reduce push fatigue risk. Microsoft Authenticator and similar enterprise apps now require the user to enter a number displayed on the login screen before approving. Best for: enterprise SSO environments where user experience matters and push-fatigue mitigations are enabled.<\/p>\n<h3 id=\"hardware-security-keys-yubikey-fido2webauthn\"><span class=\"ez-toc-section\" id=\"Hardware_security_keys_YubiKey_FIDO2WebAuthn\"><\/span>Hardware security keys (YubiKey, FIDO2\/WebAuthn)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A hardware key like a YubiKey stores a private cryptographic key that never leaves the device. During login, the browser or OS sends a challenge; the key signs it with the private key and returns the signature. The server verifies the signature against the registered public key. No shared secret, no code to intercept.<\/p>\n<p><strong>Pros and cons:<\/strong><\/p>\n<ul>\n<li>\u2705 Strongly phishing-resistant: the key will not respond to a fake domain<\/li>\n<li>\u2705 No battery; works offline for the cryptographic operation<\/li>\n<li>\u2705 FIDO2\/WebAuthn is an open standard supported by all major browsers and platforms<\/li>\n<li>\u274c Hardware cost ($25\u2013$60 per key, typically)<\/li>\n<li>\u274c Lost key requires a pre-registered backup key or recovery flow<\/li>\n<li>\u274c Some legacy enterprise apps do not support WebAuthn yet<\/li>\n<\/ul>\n<blockquote>\n<p><strong>Statistic:<\/strong> One set of real-world MFA case studies reported a reduction of approximately 70% in unauthorized access events after organizations moved from SMS or basic OTP to stronger app-based or hardware-backed MFA methods.<\/p>\n<\/blockquote>\n<p>The USDA deployed FIDO-based phishing-resistant authentication for workers who could not use PIV cards \u2014 including large seasonal workforces and staff in environments requiring decontamination \u2014 demonstrating that FIDO scales even in operationally constrained settings. Best for: high-value accounts, privileged access, financial services, government, and any environment where phishing is a primary threat.<\/p>\n<h3 id=\"biometrics-fingerprint-face-recognition\"><span class=\"ez-toc-section\" id=\"Biometrics_fingerprint_face_recognition\"><\/span>Biometrics (fingerprint, face recognition)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Biometrics authenticate \u201csomething you are\u201d by comparing a live sample against a stored template. On modern devices, the comparison happens locally on a secure enclave (Apple\u2019s Secure Enclave, Android\u2019s Trusted Execution Environment) \u2014 the raw biometric data never leaves the device.<\/p>\n<p><strong>Pros and cons:<\/strong><\/p>\n<ul>\n<li>\u2705 Fast and frictionless for the user<\/li>\n<li>\u2705 Template stored locally; not transmitted over the network<\/li>\n<li>\u274c Cannot be changed if compromised (unlike a password)<\/li>\n<li>\u274c Accuracy varies by sensor quality and environmental conditions<\/li>\n<li>\u274c Regulatory constraints in some jurisdictions on biometric data storage<\/li>\n<\/ul>\n<p>Biometrics most often serve as the local unlock mechanism for a FIDO2 passkey or hardware key, not as a standalone network factor. Face ID unlocking a passkey is a strong combination. Best for: consumer devices, mobile banking, and any scenario where speed matters and the biometric is device-bound.<\/p>\n<h3 id=\"smart-cards-and-piv-certificates\"><span class=\"ez-toc-section\" id=\"Smart_cards_and_PIV_certificates\"><\/span>Smart cards and PIV certificates<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A smart card (or PIV card in federal use) stores a PKI certificate and private key on a tamper-resistant chip. The user inserts the card into a reader and enters a PIN. The card signs a challenge; the server verifies the certificate chain.<\/p>\n<p><strong>Pros and cons:<\/strong><\/p>\n<ul>\n<li>\u2705 Very high assurance; widely used in federal government under HSPD-12<\/li>\n<li>\u2705 Certificate revocation provides centralized control<\/li>\n<li>\u274c Requires card readers and middleware; high deployment complexity<\/li>\n<li>\u274c Card issuance and management infrastructure is expensive<\/li>\n<li>\u274c Not practical for remote or BYOD workforces without additional tooling<\/li>\n<\/ul>\n<p>Best for: federal agencies, defense contractors, healthcare systems with strict compliance requirements, and enterprise environments with existing PKI infrastructure.<\/p>\n<h3 id=\"pki-certificates-device-or-software-based\"><span class=\"ez-toc-section\" id=\"PKI_certificates_device_or_software-based\"><\/span>PKI certificates (device or software-based)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Similar to smart cards but the certificate lives in the device\u2019s certificate store or a software token rather than physical hardware. Mutual TLS (mTLS) uses this model for machine-to-machine authentication.<\/p>\n<p><strong>Pros and cons:<\/strong><\/p>\n<ul>\n<li>\u2705 No physical token required<\/li>\n<li>\u2705 Transparent to the user once provisioned<\/li>\n<li>\u274c Certificate lifecycle management is complex at scale<\/li>\n<li>\u274c Device theft can expose the certificate if not protected by a PIN or TPM<\/li>\n<\/ul>\n<p>Best for: enterprise device fleets managed by MDM, zero-trust network access, and API authentication between services.<\/p>\n<h3 id=\"passwordless-passkeys-fido2webauthn\"><span class=\"ez-toc-section\" id=\"Passwordless_passkeys_FIDO2WebAuthn\"><\/span>Passwordless passkeys (FIDO2\/WebAuthn)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Passkeys replace the password entirely. The device generates a public\/private key pair at registration. Login requires the user to verify locally via biometric or PIN, which unlocks the private key to sign the server\u2019s challenge. No password exists to steal or phish.<\/p>\n<p><strong>Pros and cons:<\/strong><\/p>\n<ul>\n<li>\u2705 Phishing-resistant by design: keys are domain-bound<\/li>\n<li>\u2705 No password reuse or credential stuffing risk<\/li>\n<li>\u2705 Synced passkeys (iCloud Keychain, Google Password Manager) enable cross-device use<\/li>\n<li>\u274c Recovery requires a fallback method if all devices are lost<\/li>\n<li>\u274c Enterprise adoption is still maturing; not all IdPs support passkeys fully<\/li>\n<\/ul>\n<p>Best for: consumer apps targeting mainstream users (Apple, Google, Microsoft ecosystems) and forward-looking enterprise deployments replacing legacy password flows.<\/p>\n<h3 id=\"email-otp-and-backup-codes\"><span class=\"ez-toc-section\" id=\"Email_OTP_and_backup_codes\"><\/span>Email OTP and backup codes<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Email OTP sends a code to a registered email address. Backup codes are static one-time codes generated at enrollment and stored offline by the user. Both are low-assurance options.<\/p>\n<ul>\n<li>Email OTP security depends entirely on how well the email account itself is secured.<\/li>\n<li>Backup codes are single-use and should be stored in a password manager or printed and locked away.<\/li>\n<li>Neither should serve as a primary second factor for high-value accounts.<\/li>\n<\/ul>\n<p>Best for: account recovery flows and as a last-resort fallback when primary MFA is unavailable.<\/p>\n<h2 id=\"security-best-practices-and-common-pitfalls-to-avoid\"><span class=\"ez-toc-section\" id=\"Security_best_practices_and_common_pitfalls_to_avoid\"><\/span>Security best practices and common pitfalls to avoid<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Getting MFA deployed is step one. Getting it deployed well is where most organizations stumble.<\/p>\n<p><strong>Best practices:<\/strong><\/p>\n<ul>\n<li>Prefer phishing-resistant MFA (FIDO2\/WebAuthn, hardware keys, passkeys) for privileged accounts, remote access, and any system holding sensitive data.<\/li>\n<li>Use adaptive MFA to trigger step-up authentication only when risk signals warrant it \u2014 new device, unusual location, high-value transaction.<\/li>\n<li>Require MFA on all administrative and remote access paths before anything else.<\/li>\n<li>Secure the enrollment flow: verify identity before binding a new factor to an account.<\/li>\n<li>Plan recovery before you need it: pre-register a backup key or backup method at enrollment time.<\/li>\n<li>Log and monitor authentication events; alert on repeated failed MFA attempts (a sign of push bombing or credential stuffing).<\/li>\n<\/ul>\n<p><strong>Common pitfalls:<\/strong><\/p>\n<ul>\n<li>Relying solely on SMS OTP for high-risk accounts \u2014 SIM swapping is a real and documented attack vector.<\/li>\n<li>Ignoring push fatigue: without number-matching, users under a push-bombing attack often approve the wrong request.<\/li>\n<li>Weak recovery options that effectively bypass MFA (e.g., \u201cforgot phone? answer these three security questions\u201d).<\/li>\n<li>Poor enrollment identity proofing \u2014 binding a new factor without verifying the requester\u2019s identity defeats the purpose.<\/li>\n<li>Treating MFA as a one-time project rather than an ongoing program with monitoring and periodic review.<\/li>\n<\/ul>\n<p><strong>Pro Tip:<\/strong> <em>Per <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/authentication\/concepts-azure-multi-factor-authentication-prompts-session-lifetime\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Microsoft session guidance<\/a>, MFA prompts are typically required only on first sign-in to a new device, after session expiry, or after a password change. Configure session lifetime policies to minimize re-prompting on trusted devices \u2014 this cuts friction without reducing security.<\/em><\/p>\n<h2 id=\"how-to-choose-the-right-mfa-method-for-your-situation\"><span class=\"ez-toc-section\" id=\"How_to_choose_the_right_MFA_method_for_your_situation\"><\/span>How to choose the right MFA method for your situation<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The right method depends on your threat model, your users, and your operational constraints. Work through these questions in order.<\/p>\n<p><strong>1. What is your primary threat?<\/strong><\/p>\n<ul>\n<li>Phishing or credential theft at scale \u2192 FIDO2\/WebAuthn or hardware keys, non-negotiable.<\/li>\n<li>Account takeover on consumer apps \u2192 TOTP app as a minimum; passkeys where supported.<\/li>\n<li>Insider threat or privileged access abuse \u2192 smart card\/PIV or hardware key plus session monitoring.<\/li>\n<\/ul>\n<p><strong>2. Who are your users and what devices do they control?<\/strong><\/p>\n<ul>\n<li>Corporate-managed devices \u2192 certificate-based or FIDO2 via MDM enrollment.<\/li>\n<li>BYOD or remote workers \u2192 TOTP app or push notification with number-matching.<\/li>\n<li>General consumers \u2192 TOTP app or passkeys; SMS as a fallback only.<\/li>\n<\/ul>\n<p><strong>3. What are your regulatory requirements?<\/strong><\/p>\n<ul>\n<li>Federal government: HSPD-12 mandates PIV; NIST SP 800-63B AAL2\/AAL3 sets the bar.<\/li>\n<li>Financial services: FFIEC guidance recommends risk-based, layered authentication.<\/li>\n<li>Healthcare: HIPAA does not mandate a specific MFA method but requires access controls that meet the standard.<\/li>\n<\/ul>\n<p><strong>4. What is your budget and timeline?<\/strong><\/p>\n<table>\n<thead>\n<tr>\n<th>Method<\/th>\n<th>Approximate cost<\/th>\n<th>Deployment effort<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>SMS OTP<\/td>\n<td>Near zero<\/td>\n<td>Hours<\/td>\n<\/tr>\n<tr>\n<td>TOTP app<\/td>\n<td>Near zero<\/td>\n<td>Days<\/td>\n<\/tr>\n<tr>\n<td>Push notification<\/td>\n<td>Per-user SaaS fee<\/td>\n<td>Days to weeks<\/td>\n<\/tr>\n<tr>\n<td>Hardware key (FIDO2)<\/td>\n<td>$25\u2013$60 per key<\/td>\n<td>Weeks (procurement + enrollment)<\/td>\n<\/tr>\n<tr>\n<td>Smart card \/ PIV<\/td>\n<td>$10\u2013$30 per card + reader + PKI infrastructure<\/td>\n<td>Months<\/td>\n<\/tr>\n<tr>\n<td>Passkeys<\/td>\n<td>Near zero (platform-native)<\/td>\n<td>Weeks (IdP configuration)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>5. What is your recovery plan?<\/strong><\/p>\n<ul>\n<li>Every deployment needs a tested recovery path that does not bypass MFA.<\/li>\n<li>Pre-register a backup hardware key or backup TOTP device at enrollment.<\/li>\n<li>For enterprise, use a helpdesk-verified identity-proofing step before resetting any factor.<\/li>\n<\/ul>\n<p><strong>6. Can you use <a href=\"https:\/\/logmeonce.com\/two-factor-authentication\" target=\"_blank\" rel=\"noopener\">two-factor authentication<\/a> as a starting point?<\/strong><\/p>\n<ul>\n<li>Yes. Start with TOTP for all accounts, then layer hardware keys for privileged access as the program matures.<\/li>\n<\/ul>\n<h2 id=\"how-logmeonce-approaches-mfa-and-passwordless-authentication\"><span class=\"ez-toc-section\" id=\"How_Logmeonce_approaches_MFA_and_passwordless_authentication\"><\/span>How Logmeonce approaches MFA and passwordless authentication<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Logmeonce is built around the premise that strong authentication should not require a PhD to deploy. The platform supports the full spectrum of MFA methods covered in this article, with centralized management that works for a single user or a large enterprise team.<\/p>\n<p>Key capabilities relevant to MFA and passwordless:<\/p>\n<ul>\n<li><strong>Passwordless authentication:<\/strong> Logmeonce\u2019s <a href=\"https:\/\/logmeonce.com\/blog\/press_release\/logmeonce-announces-password-less-authentication-version-5-2-protecting-identities-on-apple-ios-android-microsoft-windows-and-mac-os\" target=\"_blank\" rel=\"noopener\">passwordless version 5.2<\/a> supports FIDO-based passkeys across iOS, Android, Windows, and macOS \u2014 covering the major platforms where users actually work.<\/li>\n<li><strong>Hardware key support:<\/strong> Compatible with FIDO2 hardware tokens, so organizations moving toward phishing-resistant MFA can do so within a single management console.<\/li>\n<li><strong>SSO integration:<\/strong> Single sign-on ties MFA enforcement to every connected application, so one strong authentication event covers the user\u2019s entire session rather than requiring repeated logins.<\/li>\n<li><strong>Recovery and enrollment flows:<\/strong> Centralized administration lets IT teams manage factor enrollment, set recovery policies, and audit authentication events from one dashboard.<\/li>\n<li><strong>Individual to enterprise scale:<\/strong> Plans cover personal users who want to secure personal accounts, SMBs deploying MFA for the first time, and enterprise teams with compliance requirements.<\/li>\n<\/ul>\n<p>For organizations evaluating a move from SMS OTP to TOTP or hardware keys, Logmeonce provides a migration path that does not require ripping out existing infrastructure.<\/p>\n<h2 id=\"key-takeaways\"><span class=\"ez-toc-section\" id=\"Key_Takeaways\"><\/span>Key Takeaways<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Phishing-resistant MFA methods \u2014 FIDO2 hardware keys and passkeys \u2014 are the strongest options available, and organizations that move from SMS OTP to app-based or hardware-backed MFA typically see a reduction of approximately 70% in unauthorized access.<\/p>\n<table>\n<thead>\n<tr>\n<th>Point<\/th>\n<th>Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Prefer phishing-resistant MFA<\/td>\n<td>Use FIDO2 hardware keys or passkeys for privileged and high-risk accounts.<\/td>\n<\/tr>\n<tr>\n<td>TOTP apps beat SMS<\/td>\n<td>Google Authenticator, Authy, and Microsoft Authenticator are free and far harder to intercept than SMS codes.<\/td>\n<\/tr>\n<tr>\n<td>Adaptive MFA reduces friction<\/td>\n<td>Trigger step-up authentication only on new devices or elevated-risk activity, not every login.<\/td>\n<\/tr>\n<tr>\n<td>Plan recovery before deployment<\/td>\n<td>Pre-register a backup factor at enrollment; a recovery path that bypasses MFA defeats its purpose.<\/td>\n<\/tr>\n<tr>\n<td>Logmeonce covers the full stack<\/td>\n<td>Logmeonce supports passwordless passkeys, hardware keys, SSO, and centralized enrollment management.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"the-trade-off-nobody-talks-about-enough\"><span class=\"ez-toc-section\" id=\"The_trade-off_nobody_talks_about_enough\"><\/span>The trade-off nobody talks about enough<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The security community spent years telling people that any MFA is better than no MFA. That was true and necessary \u2014 it got millions of accounts off password-only authentication. But it created a secondary problem: organizations deployed SMS OTP, checked the \u201cMFA enabled\u201d box, and stopped there.<\/p>\n<p>SMS MFA is not a destination. It is a starting point that has a known, documented attack surface. SIM swapping is not a theoretical threat; it has been used in high-profile account takeovers across financial services and crypto exchanges. The gap between SMS OTP and a FIDO2 hardware key is not marginal \u2014 it is the difference between a factor that can be intercepted in real time and one that is cryptographically bound to a specific domain and device.<\/p>\n<p>The harder truth is that the weakest link in most MFA deployments is not the factor itself \u2014 it is the recovery flow. An organization can deploy YubiKeys for every employee and still be wide open if the account recovery process accepts a phone call and a few security questions. Attackers know this. They target the recovery path precisely because the front door is now locked.<\/p>\n<p>The practical move: treat enrollment and recovery as security-critical as the factor itself. Require identity verification before any factor reset. Pre-register backup keys. Audit recovery events the same way you audit failed logins. That is where the real security work happens, and most guides skip it entirely.<\/p>\n<h2 id=\"logmeonce-makes-phishing-resistant-mfa-practical\"><span class=\"ez-toc-section\" id=\"Logmeonce_makes_phishing-resistant_MFA_practical\"><\/span>Logmeonce makes phishing-resistant MFA practical<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Deploying FIDO2 passkeys, hardware key support, and SSO-integrated MFA across your accounts does not have to mean months of infrastructure work. Logmeonce centralizes the whole process \u2014 factor enrollment, session policy, recovery flows, and audit logging \u2014 in one platform that scales from a single user to an enterprise team.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/csuxjmfbwmkxiegfpljm.supabase.co\/storage\/v1\/object\/public\/blog-images\/organization-6456\/1760417791460_logmeonce.jpg\" alt=\"Logmeonce\" title=\"\"><\/p>\n<p>The platform\u2019s passwordless authentication covers iOS, Android, Windows, and macOS, and hardware key compatibility means you can move toward phishing-resistant MFA without replacing your existing identity infrastructure. If you are ready to move past SMS OTP and toward authentication that actually holds up under attack, visit the <a href=\"https:\/\/logmeonce.com\/cybersecurity\" target=\"_blank\" rel=\"noopener\">Logmeonce cybersecurity page<\/a> to see plans and start a free trial.<\/p>\n<h2 id=\"authoritative-sources-and-further-reading\"><span class=\"ez-toc-section\" id=\"Authoritative_sources_and_further_reading\"><\/span>Authoritative sources and further reading<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>Standards and official guidance:<\/strong><\/p>\n<ul>\n<li>NIST SP 800-63B \/ NIST Glossary: Multi-Factor Authentication \u2014 the primary U.S. standard for digital identity assurance levels and factor definitions; the baseline for any serious MFA policy.<\/li>\n<li>CISA: Multi-Factor Authentication \u2014 CISA\u2019s MFA resource hub, including guidance on phishing-resistant methods and implementation checklists.<\/li>\n<li>CISA: Phishing-Resistant MFA Success Story \u2014 USDA FIDO Implementation \u2014 a detailed case study showing how FIDO-based MFA replaced weaker methods across a large, operationally complex federal agency.<\/li>\n<\/ul>\n<p><strong>Product documentation and technical guidance:<\/strong><\/p>\n<ul>\n<li>Microsoft: What Is Multi-Factor Authentication? \u2014 clear explanation of TOTP, push, and other methods; good starting point for end-user communication.<\/li>\n<li>Microsoft: Azure MFA Prompts and Session Lifetime \u2014 explains when MFA prompts fire and how to configure session policies to reduce friction.<\/li>\n<li>Palo Alto Networks Cyberpedia: What Is Adaptive MFA? \u2014 practical overview of context-aware authentication and how adaptive policies work in enterprise environments.<\/li>\n<\/ul>\n<p><strong>Real-world examples and method surveys:<\/strong><\/p>\n<ul>\n<li>Supertokens: Real-World Examples of Multi-Factor Authentication \u2014 survey of MFA deployments across banking, healthcare, education, and e-commerce, with outcome data.<\/li>\n<li><a href=\"https:\/\/www.ffiec.gov\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">FFIEC Authentication Guidance<\/a> \u2014 financial sector authentication standards referenced by U.S. banks and credit unions.<\/li>\n<li><a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/statutes\/gramm-leach-bliley-act\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">FTC: Gramm-Leach-Bliley Act<\/a> \u2014 the federal statute that drives MFA requirements in financial services; useful context for compliance-driven deployments.<\/li>\n<\/ul>\n\n<div style=\"font-size: 0px; height: 0px; line-height: 0px; margin: 0; padding: 0; clear: both;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Discover practical examples of MFA, enhancing your security with methods like SMS OTPs, hardware keys, and biometrics. Learn now!<\/p>\n","protected":false},"author":17,"featured_media":248183,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[19737],"tags":[6622,16590,6061,21144,20782,20522,9865,10512,20628,7465,21145,20484],"class_list":["post-71777","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-two-factor-authentication","tag-design","tag-creative-writing","tag-dance","tag-digital-arts","tag-graduate-school","tag-masters-degree","tag-photography","tag-programs","tag-programs-mfa","tag-sculpture","tag-theater-arts","tag-visual-arts"],"acf":[],"_links":{"self":[{"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/posts\/71777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/comments?post=71777"}],"version-history":[{"count":1,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/posts\/71777\/revisions"}],"predecessor-version":[{"id":248182,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/posts\/71777\/revisions\/248182"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/media\/248183"}],"wp:attachment":[{"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/media?parent=71777"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/categories?post=71777"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/logmeonce.com\/resources\/wp-json\/wp\/v2\/tags?post=71777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}