What is multi-factor authentication?¶
Multi-factor authentication — MFA — requires more than one kind of authentication factor before access is granted.
In everyday terms, it usually means combining something like a password with a phone, authenticator app or security key.
That can give an investigator extra evidence about how access was approved.
The common factor types¶
| Factor type | Typical example |
|---|---|
| Something you know | Password or PIN |
| Something you have | Phone, authenticator app or security key |
| Something you are | Biometric check accepted by a device |
Two passwords are still the same kind of factor.
A password plus an authenticator-app approval normally combines two different factor types.
What might the records show?¶
A provider may record:
device-6142approved=2026-08-17 13:58:18 UTCsession=S-4812That can be useful because it links the access event to another factor or device.
MFA can strengthen attribution without solving it¶
If the second factor was approved on a phone recovered from a suspect, that may be significant.
But still ask:
- who controlled the phone at the time;
- whether the approval was deliberate;
- whether another factor had recently been enrolled;
- whether recovery had been used;
- whether the session already existed; and
- whether the factor could have been shared or compromised.
Codes can be phished. Phones can be taken over. Prompts can be approved by mistake. Security keys can be shared or stolen.
Those possibilities matter only where they genuinely fit the evidence.
Check factor changes around suspicious access¶
If an account is compromised, an offender may try to add a new authentication factor or replace a recovery method.
So preserve:
- factor enrolment;
- factor removal;
- recovery changes;
- trusted-device changes;
- session revocation; and
- the exact time of the disputed access.
That may show not only that MFA was used, but who had changed the security setup before it happened.
The practical point is: MFA gives you more than one security event to follow. Trace the factors, devices and changes around the login rather than treating “MFA passed” as a person's identity.