Cybersecurity Awareness Fact Sheet
For public distribution – Updated May 2024
Multi-factor authentication (MFA) is a security system that requires more than one method of authentication to verify your identity for a login or other transaction. It adds an extra layer of protection.
Authentication methods include something you know, like a password or PIN number; something you have, like a PKI card or secure token; or something you are, like facial recognition or a fingerprint scan.
Tips & Best Practices
- Enable MFA whenever available, including on email, financial platforms, social media, online stores, and gaming and streaming accounts.
- A recommended method of MFA is via an authenticator app (e.g., Google Authenticator, Microsoft Authenticator, Duo Mobile) that will generate a code or request login verification.
- When possible, avoid choosing text message (SMS) as your primary method of MFA because malicious actors can intercept text messages.
- Never respond to a text message or phone call that asks for your MFA code, and only approve MFA log-in requests that you initiated yourself.
- When possible, incorporate biometric verification, like facial recognition or fingerprint scanning, as one method of MFA.
- Set up multiple methods of MFA to maintain account access. If you selected the app method but lose or replace your device, you’ll be able to use a secondary method of MFA to access your account.
Resources
- Visit the 2FA Directory for a catalog of platforms that use MFA and instructions to enable it.
- Explore CISA’s More Than a Password webpage.
Diplomatic Security Service
Directorate of Cyber and Technology Security
U.S. Department of State




