What Is MFA / 2FA (Multi-Factor Authentication)? | NerdSquad

MFA / 2FA (Multi-Factor Authentication / Two-Factor Authentication)

MFA (multi-factor authentication) asks for a second proof of identity, such as a code or an app approval on your phone, before anyone can sign in with your password. It is one of the most effective ways to stop stolen passwords from turning into stolen accounts.

You've probably used it already. You type your password, then your phone buzzes with a six-digit code, or you tap "Approve" in an app, or you touch a small USB key. That second step, whatever form it takes, is multi-factor authentication.

What do MFA and 2FA stand for?

MFA stands for multi-factor authentication. 2FA (two-factor authentication) is the same idea with exactly two factors. MFA is the broader term and covers two or more. In everyday use people treat them as interchangeable, and for most small and midsize businesses two factors is the right fit.

The simple way to think about it

Authentication factors fall into three categories:

  • Something you know: a password or PIN
  • Something you have: your phone, a hardware key or a smart card
  • Something you are: a fingerprint or face scan

A password alone is one factor. MFA adds at least one more from a different category. That matters because passwords get phished, guessed, reused and leaked in data breaches all the time. A stolen password is far less useful to an attacker who would also need your phone.

Microsoft has reported that MFA blocks more than 99.9% of automated account compromise attacks against its accounts. For the effort and cost involved, few security controls do more.

What the second factor looks like

The most common options for businesses:

  • Authenticator apps such as Microsoft Authenticator or Google Authenticator. They generate a rotating code or send a push notification to approve. This is the standard for most business environments, ideally with number matching turned on.
  • Text message (SMS) codes. Better than nothing, but the weakest option, because phone numbers can be hijacked through SIM swapping. Current guidance discourages SMS as a primary method where stronger options are available.
  • Hardware security keys. A small physical device you plug in or tap. These are the strongest option and resist phishing, which makes them common for administrators and high-compliance environments.
  • Biometrics such as a fingerprint or face unlock on a phone or laptop, usually as part of a passwordless sign-in or paired with another factor.

MFA and compliance

Most frameworks that NerdSquad clients work under either require MFA or treat it as an expected safeguard:

  • HIPAA: the current Security Rule requires access controls and person-or-entity authentication but does not name MFA specifically. Risk assessments usually point to MFA for systems that hold patient data. A Security Rule update proposed in January 2025 would make MFA an explicit requirement; it is a proposal, not a final rule. See how we help medical and dental practices with HIPAA.
  • PCI DSS v4.0.1: requires MFA for all access into the cardholder data environment, a requirement that became mandatory on March 31, 2025.
  • FTC Safeguards Rule (GLBA): requires MFA for anyone accessing customer information systems at covered non-bank financial institutions such as tax preparers and mortgage brokers.
  • CMMC and NIST SP 800-171: require MFA for privileged accounts and for network access to non-privileged accounts.
  • SOC 2 and cyber insurance: auditors and insurers commonly expect MFA on email, remote access and administrator accounts. Applications without it are often flagged or declined.

For more detail, see how we help with compliance requirements like HIPAA, PCI and SOC 2. NerdSquad is not a law firm; confirm your obligations with your compliance counsel.

Where NerdSquad comes in

NerdSquad Managed IT Services is a Managed Service Provider (MSP), and we set up and enforce MFA as a standard part of managed IT services: Microsoft 365, remote access, line-of-business applications and anything else that touches sensitive data. Through our Microsoft 365 support we also turn on the policies that make MFA harder to bypass. We handle the rollout too: telling staff what's changing, walking them through setup and keeping the switch from turning into a week of locked-out users.

MFA pairs naturally with single sign-on (SSO) and a Zero Trust security model. If your team isn't using MFA on email and remote access today, that is the first conversation we'd want to have.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Cybersecurity services for businesses