Skip to content
AI-016 Accounts & Identity

Accounts & IdentityAI-016

What is multi-factor authentication?

Multi-factor authentication requires more than one type of authentication factor before access is granted. It can make account compromise harder, but it does not prove that the registered account holder personally completed the login.

The different factor types

Authentication factors are commonly grouped as:

  • something the user knows, such as a password or PIN;
  • something the user has, such as a phone, authenticator application or physical security key; and
  • something the user is, such as a fingerprint or facial-recognition result.

Two passwords are not normally multi-factor authentication because both are the same type of factor. A password followed by an authenticator-app code usually is, because it combines knowledge with possession of a device or application.

Why it matters to an investigation

A successful multi-factor event may provide more detail than a password-only login. It may show that the required factors were presented or approved and may help identify:

  • the authentication method;
  • the device receiving a code or prompt;
  • the telephone number or authenticator account involved;
  • a physical security key;
  • changes to security settings; and
  • the sequence of events leading to access.

This can strengthen an attribution assessment, particularly where the second factor is linked to a specific device and there is evidence showing who controlled that device.

Multi-factor authentication can still be defeated

The presence of multi-factor authentication should not be treated as conclusive. Access may still occur where:

  • a code is obtained through phishing;
  • a telephone number is taken over;
  • a user approves a fraudulent login prompt;
  • a device or security key is stolen;
  • a new factor is added through account recovery; or
  • an existing authenticated session remains usable.

The provider may also distinguish between a new multi-factor challenge and access through a session that was authenticated earlier.

What to check

Establish:

  • which factors were required;
  • which factors were actually used;
  • which device received or approved the request;
  • whether a code, push approval or physical key was involved;
  • whether the account’s telephone number, trusted devices or authentication settings had changed; and
  • who controlled the relevant factor at the time.

Avoid saying that multi-factor authentication identifies the person. It shows that the configured authentication requirements were satisfied. Personal attribution depends on the surrounding evidence.

Key takeaway

Multi-factor authentication may strengthen the evidential link between access and a device or security factor, but the investigator must still establish who controlled that factor at the relevant time.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.