Multi-factor authentication requires two or more different types of evidence to verify a user’s identity.

Identity is checked in layers

MFA asks for evidence from separate categories: something known, possessed, or inherent. A password plus a security key is different from two passwords.

Access policies need context

Organizations can require stronger factors for administrators, unfamiliar devices, or sensitive actions. Enrollment, recovery, and emergency access must be designed alongside the sign-in rule.