{"id":616,"date":"2026-08-11T13:28:33","date_gmt":"2026-08-11T13:28:33","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=616"},"modified":"2026-08-11T13:28:33","modified_gmt":"2026-08-11T13:28:33","slug":"mfa","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/mfa\/","title":{"rendered":"MFA Explained: Factors, Methods and Phishing Risk"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: MFA\n     Same design system as the VAPT glossary page.\n     Paste the whole block into one Custom HTML block. No H1 (WP adds it).\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">MFA stands for multi-factor authentication: confirming a user&#8217;s identity with two or more independent types of evidence, so that a stolen password alone cannot grant access to an account.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Access &amp; identity<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>MFA requires at least two factors from different categories: something the user knows, something the user has, or something the user is. Because the categories are independent, an attacker who obtains one still cannot authenticate without compromising the second.<\/p>\n<\/div>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#factors\">The three authentication factors<\/a><\/li>\n    <li><a href=\"#blocks\">What MFA prevents<\/a><\/li>\n    <li><a href=\"#methods\">Comparing MFA methods<\/a><\/li>\n    <li><a href=\"#compliance\">Where frameworks require MFA<\/a><\/li>\n    <li><a href=\"#limits\">Known limitations<\/a><\/li>\n    <li><a href=\"#osto\">How Osto handles MFA<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"factors\">The three authentication factors<\/h2>\n\n<p>Two prompts do not automatically make two factors. A password followed by a security question remains a single category, because both are items of knowledge and both are exposed by the same breach. Multi-factor authentication requires evidence from different categories.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Something you know<\/p>\n    <p class=\"g\">Knowledge factor<\/p>\n    <p>Password, PIN or security question. Exposed by data breaches, phishing and password reuse.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Something you have<\/p>\n    <p class=\"g\">Possession factor<\/p>\n    <p>A registered phone running an authenticator application, a hardware security key, or a passkey stored on a device.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Something you are<\/p>\n    <p class=\"g\">Inherence factor<\/p>\n    <p>Fingerprint or facial recognition. In most systems this unlocks a key held on the device rather than being transmitted to the server.<\/p>\n  <\/div>\n<\/div>\n\n<div class=\"callout\">\n  <p class=\"k\">2FA and MFA<\/p>\n  <p>2FA refers to authentication using exactly two factors. MFA is the broader term covering two or more. Most implementations described as MFA use two factors, and auditors and enterprise buyers treat the terms as equivalent.<\/p>\n<\/div>\n\n<h2 id=\"blocks\" class=\"c-sage\">What MFA prevents<\/h2>\n\n<p>MFA is designed to defeat credential reuse. Passwords are exposed in third-party breaches and then tested against other services, where users have often reused them. Without a second factor, a valid password is sufficient to authenticate.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 300\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"With a password alone, a stolen credential authenticates successfully. With MFA, the attempt is stopped at the second factor.\">\n  <defs>\n    <marker id=\"mf1\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#4a52a8\"\/><\/marker>\n    <marker id=\"mf2\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#8a90a8\"\/><\/marker>\n  <\/defs>\n\n  <text x=\"18\" y=\"28\" font-family=\"Inter,sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#4a52a8\">Password only<\/text>\n  <text x=\"18\" y=\"49\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">A single credential controls access<\/text>\n  <rect x=\"8\" y=\"62\" width=\"356\" height=\"218\" rx=\"18\" fill=\"#f4f5fd\"\/>\n\n  <rect x=\"44\" y=\"88\" width=\"284\" height=\"42\" rx=\"10\" fill=\"#ffffff\"\/>\n  <text x=\"186\" y=\"114\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#4a52a8\">Stolen password<\/text>\n  <line x1=\"186\" y1=\"136\" x2=\"186\" y2=\"176\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#mf1)\"\/>\n  <rect x=\"44\" y=\"184\" width=\"284\" height=\"42\" rx=\"10\" fill=\"#1c267a\"\/>\n  <text x=\"186\" y=\"210\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"600\" fill=\"#ffffff\">Account and customer data<\/text>\n  <text x=\"186\" y=\"256\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"600\" fill=\"#4a52a8\">Access granted<\/text>\n\n  <text x=\"406\" y=\"28\" font-family=\"Inter,sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#1c267a\">With MFA<\/text>\n  <text x=\"406\" y=\"49\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">A second, independent factor is also required<\/text>\n  <rect x=\"396\" y=\"62\" width=\"356\" height=\"218\" rx=\"18\" fill=\"#f1f7fb\"\/>\n\n  <rect x=\"432\" y=\"88\" width=\"284\" height=\"38\" rx=\"10\" fill=\"#ffffff\"\/>\n  <text x=\"574\" y=\"112\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#2f6a89\">Stolen password<\/text>\n  <line x1=\"574\" y1=\"132\" x2=\"574\" y2=\"152\" stroke=\"#8a90a8\" stroke-width=\"2.5\" marker-end=\"url(#mf2)\"\/>\n  <rect x=\"432\" y=\"160\" width=\"284\" height=\"38\" rx=\"10\" fill=\"#1c267a\"\/>\n  <text x=\"574\" y=\"184\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"600\" fill=\"#ffffff\">Second factor required<\/text>\n  <line x1=\"490\" y1=\"210\" x2=\"658\" y2=\"210\" stroke=\"#8a90a8\" stroke-width=\"3\" stroke-linecap=\"round\"\/>\n  <rect x=\"432\" y=\"222\" width=\"284\" height=\"34\" rx=\"10\" fill=\"#e9ebf1\"\/>\n  <text x=\"574\" y=\"244\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">Account and customer data<\/text>\n  <text x=\"574\" y=\"278\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"600\" fill=\"#1c267a\">Access denied<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>MFA does not strengthen the password. It makes the password insufficient on its own.<\/figcaption>\n<\/figure>\n\n<h2 id=\"methods\" class=\"c-apri\">Comparing MFA methods<\/h2>\n\n<p>Methods differ in strength. The distinction that matters most is phishing resistance: whether the factor can be captured and replayed by an attacker operating a proxy between the user and the legitimate login page.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 300\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"MFA methods ranked by phishing resistance, with passkeys and biometrics above the phishing-resistant line.\">\n  <text x=\"20\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">RESISTANCE TO PHISHING<\/text>\n\n  <rect x=\"230\" y=\"44\" width=\"470\" height=\"34\" rx=\"9\" fill=\"#1c267a\"\/>\n  <text x=\"216\" y=\"66\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">Passkey or security key<\/text>\n  <text x=\"246\" y=\"66\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#ffffff\">Bound to the real domain, cannot be replayed<\/text>\n\n  <rect x=\"230\" y=\"90\" width=\"430\" height=\"34\" rx=\"9\" fill=\"#3a4795\"\/>\n  <text x=\"216\" y=\"112\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">Biometrics<\/text>\n  <text x=\"246\" y=\"112\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#ffffff\">Unlocks a key held on the device<\/text>\n\n  <line x1=\"120\" y1=\"140\" x2=\"740\" y2=\"140\" stroke=\"#3a6f5d\" stroke-width=\"2\" stroke-dasharray=\"7 5\"\/>\n  <rect x=\"120\" y=\"128\" width=\"168\" height=\"24\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"204\" y=\"145\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" letter-spacing=\".6\" fill=\"#3a6f5d\">PHISHING RESISTANT<\/text>\n\n  <rect x=\"230\" y=\"164\" width=\"270\" height=\"34\" rx=\"9\" fill=\"#c2d9ec\"\/>\n  <text x=\"216\" y=\"186\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">Push approval<\/text>\n  <text x=\"246\" y=\"186\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#25547a\">Approval can be fatigued into a yes<\/text>\n\n  <rect x=\"230\" y=\"210\" width=\"240\" height=\"34\" rx=\"9\" fill=\"#dfe3f5\"\/>\n  <text x=\"216\" y=\"232\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">Authenticator app<\/text>\n  <text x=\"246\" y=\"232\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#3d4590\">Code can be relayed to a proxy site<\/text>\n\n  <rect x=\"230\" y=\"256\" width=\"130\" height=\"34\" rx=\"9\" fill=\"#eef0f4\"\/>\n  <text x=\"216\" y=\"278\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#0f1538\">SMS or email OTP<\/text>\n  <text x=\"246\" y=\"278\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">SIM swap, mailbox<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full chart. <\/span>Everything below the line can be captured and replayed by an attacker proxying the real login page. Everything above it cannot.<\/figcaption>\n<\/figure>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Method<\/th><th>How it works<\/th><th>Recommended use<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr>\n      <td><strong>SMS or email OTP<\/strong><\/td>\n      <td>A one-time code sent to a phone number or mailbox<\/td>\n      <td>Only where no alternative exists. Vulnerable to SIM swap and mailbox compromise<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>Authenticator application<\/strong><\/td>\n      <td>A rotating six-digit code generated on the device (TOTP)<\/td>\n      <td>Minimum standard for all employee accounts<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>Push approval<\/strong><\/td>\n      <td>An approve or deny prompt sent to a registered device<\/td>\n      <td>Acceptable, provided number matching is enabled<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>Passkey or security key<\/strong><\/td>\n      <td>A cryptographic key bound to the legitimate domain (FIDO2, WebAuthn)<\/td>\n      <td>Required for administrative, production and finance access<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>Biometrics<\/strong><\/td>\n      <td>Fingerprint or facial recognition unlocking a key stored on the device<\/td>\n      <td>Used together with passkeys, not as a standalone factor<\/td>\n    <\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"compliance\" class=\"c-plum\">Where frameworks require MFA<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Framework<\/th><th>Status<\/th><th>Where it appears<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr>\n      <td><strong>PCI DSS v4.0<\/strong><\/td>\n      <td><span class=\"pill p-req\">Required<\/span><\/td>\n      <td>Requirement 8.4: MFA for all remote access and for all access into the cardholder data environment.<\/td>\n    <\/tr>\n    <tr>\n      <td><strong><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>:2022<\/strong><\/td>\n      <td><span class=\"pill p-exp\">Expected<\/span><\/td>\n      <td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A<\/a> 8.5 (secure authentication) and A 5.17 (authentication information).<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>SOC 2<\/strong><\/td>\n      <td><span class=\"pill p-exp\">Expected<\/span><\/td>\n      <td>Not named in the <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-controls-cc1-cc9\/\">Trust Services Criteria<\/a>. Auditors treat MFA as the standard logical access control under CC6.1.<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>DPDP Act, 2023<\/strong><\/td>\n      <td><span class=\"pill p-imp\">Implied<\/span><\/td>\n      <td>Requires reasonable security safeguards. MFA on systems holding personal data is the baseline expectation.<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>Cyber insurance<\/strong><\/td>\n      <td><span class=\"pill p-ask\">Asked<\/span><\/td>\n      <td>Most insurers require MFA on email, remote access and administrative accounts before issuing a quote.<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>Buyer questionnaires<\/strong><\/td>\n      <td><span class=\"pill p-ask\">Asked<\/span><\/td>\n      <td>Whether MFA is enforced on administrative accounts, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sso\/\">single sign-on<\/a> and production access, and whether exceptions exist.<\/td>\n    <\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"limits\" class=\"c-sky\">Known limitations<\/h2>\n\n<p>MFA raises the cost of an attack but does not eliminate it. Three techniques defeat code-based methods: proxy phishing, which captures the session cookie after the user legitimately approves; repeated push notifications, which rely on the user eventually approving one; and SIM swap, which transfers a phone number to an attacker-controlled device.<\/p>\n\n<p>Coverage is more often the weakness than method. An exempted contractor, a service account or a legacy system outside single sign-on provides the same result as no MFA at all.<\/p>\n\n<div class=\"callout c-plum\">\n  <p class=\"k\">Commonly missed accounts<\/p>\n  <p>MFA on the identity provider does not extend to systems outside it. Direct database access, SSH into production and administrative panels that predate single sign-on should be verified first.<\/p>\n<\/div>\n\n<h2 id=\"osto\">How Osto handles MFA<\/h2>\n\n<p>Osto enforces MFA at the network layer rather than relying on each application. The ZTNA module places cloud servers and internal resources behind a private domain, and those resources remain unreachable unless the Osto endpoint agent is installed and MFA is satisfied. Systems that would otherwise sit outside single sign-on are covered by default.<\/p>\n\n<p>The IAM module manages identity and access across the stack. Because authentication events are recorded in the same platform as endpoint, WAF and cloud activity, a suspicious sign-in can be correlated with subsequent behaviour rather than reviewed in isolation.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Find the accounts your MFA policy does not cover<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto gates internal resources behind ZTNA with agent and MFA enforcement, and manages identity across the stack. Tell us your scope and we will tailor a plan.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Deploys in hours &middot; No dedicated security team required &middot; One platform, everything<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does MFA stand for?<\/summary>\n  <p>MFA stands for multi-factor authentication. It means confirming a user&#8217;s identity with two or more independent types of evidence, drawn from different categories: something the user knows, something the user has, or something the user is.<\/p>\n<\/details>\n\n<details>\n  <summary>Is MFA the same as 2FA?<\/summary>\n  <p>2FA uses exactly two factors. MFA covers two or more. Most implementations use two, and auditors, insurers and enterprise buyers treat the terms as equivalent.<\/p>\n<\/details>\n\n<details>\n  <summary>Which MFA method is the most secure?<\/summary>\n  <p>Passkeys and hardware security keys based on FIDO2 or WebAuthn, because the credential is cryptographically bound to the legitimate domain and cannot be replayed against a fraudulent login page. Authenticator applications are the minimum standard. SMS is the weakest common option, as a SIM swap transfers the number to an attacker.<\/p>\n<\/details>\n\n<details>\n  <summary>Is MFA required for SOC 2?<\/summary>\n  <p>The Trust Services Criteria do not name MFA specifically. Auditors treat it as the standard control for logical access under CC6.1, and an environment without MFA on administrative accounts will normally result in a finding.<\/p>\n<\/details>\n\n<details>\n  <summary>Can MFA be bypassed?<\/summary>\n  <p>Yes. Proxy phishing can capture a session cookie after a legitimate approval, repeated push notifications rely on a user approving one, and SIM swap defeats SMS codes. Phishing-resistant factors on high-value accounts, combined with complete coverage and no exemptions, address most of these cases.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> IAM &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sso\/\">SSO<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">Zero Trust Network Access<\/a> &middot; RBAC &middot; Phishing &middot; Passwordless Authentication<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MFA stands for multi-factor authentication: confirming a user&#8217;s identity with two or more independent types of evidence, so that a\u2026<\/p>\n","protected":false},"author":8,"featured_media":617,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[205,208,203,204,207,206,210,209],"class_list":["post-616","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-2fa","tag-fido2","tag-mfa","tag-multi-factor-authentication","tag-passkeys","tag-phishing-resistant-mfa","tag-totp","tag-webauthn"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/616","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=616"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/616\/revisions"}],"predecessor-version":[{"id":618,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/616\/revisions\/618"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/617"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}