What Is Multi-Factor Authentication (MFA) and Why Should You Use It?

Tags security

Overview

Multi-factor authentication, commonly called MFA, adds another verification step when you sign in to an account. Instead of relying only on a password, MFA asks you to provide a second form of proof that you are the person trying to sign in.

MFA is important because passwords can be guessed, stolen, reused, or exposed in a data breach. If someone obtains your password, MFA can still prevent that person from accessing your account.

MFA does not replace a strong, unique password. The two protections work together.

How It Works

An account using MFA asks for two or more types of verification. These may include:

  • Something you know, such as a password or PIN.
  • Something you have, such as a phone, authenticator app, hardware security key, or one-time code.
  • Something you are, such as a fingerprint or face scan.

Common MFA methods include:

  • Approving a notification in an authenticator app.
  • Entering a one-time code from an authenticator app, text message, or hardware token.
  • Using a hardware security key or passkey.
  • Using a fingerprint, face scan, or other biometric method.

The available methods depend on the account or service. When you can choose, use the strongest method the service supports. Security keys and passkeys are generally harder to phish than verification codes that can be copied, intercepted, or shared.

How to Protect Yourself

  • Approve only MFA requests that you initiated. If you did not just enter your password and try to sign in, do not approve the request.
  • Review the information in the prompt. Some MFA notifications show the application, location, or device involved in the sign-in.
  • Never share an MFA code. A legitimate support representative should not ask you to read a verification code to them or send it in email, text, or chat.
  • Do not approve repeated prompts just to make them stop. Attackers sometimes send many requests in the hope that a person will eventually approve one. This is sometimes called MFA fatigue or MFA bombing.
  • Protect the device used for MFA. Use a screen lock, install updates, and do not allow others to use your authenticator app.
  • Store recovery codes securely. Do not keep them in an unprotected document, email message, or shared location.
  • Set up a backup method when the service allows it. A backup method can help you regain access if your phone is lost, replaced, or unavailable.

What You Should Do at UM

Use MFA whenever it is required or available for a UM account or service.

Only approve an MFA prompt when you have personally started the sign-in. UM IT staff will not ask you to share an MFA code or approve an unexpected prompt to verify your identity.

If you receive an unexpected MFA request for a UM account:

  1. Deny or reject the request. Do not approve it.
  2. Do not share any code shown on your phone or authenticator.
  3. Change your UM password through the normal UM account-management process using a trusted device.
  4. Contact the UM IT Helpdesk or UM Information Security Office. This is especially important if you approved the request, entered information on an unfamiliar sign-in page, or continue to receive prompts.

An unexpected prompt may mean that someone has your password and is attempting to sign in. Reporting it promptly allows UM staff to review the account and provide the correct recovery steps.

If you replace or lose the device you use for MFA, contact the UM IT Helpdesk for assistance restoring access. Do not ask another person to approve prompts for you or attempt to bypass MFA.

Additional Questions

For help with a UM account, an unexpected UM MFA prompt, or an MFA device change, contact the UM IT Helpdesk and the UM Information Security Office.

For a personal account, use the account provider's official security or account-recovery process. If the account contains banking or payment information and you notice unauthorized activity, contact the financial institution directly using a trusted phone number or website.

Additional Resources

Was this helpful?
0 reviews