WHAT YOU WILL LEARN
Learning objectives
- Distinguish independent factors from two passwords
- Recognize unexpected authentication prompts
- Prepare a safe recovery method
Use independent factors
A password and a PIN are both knowledge factors. MFA combines different kinds of proof, such as a password with a registered device. Products may use biometrics to unlock a device-held credential; the implementation matters more than counting two visible screens.
Prefer phishing-resistant methods
Authenticator codes improve many password-only sign-ins, but an attacker can still trick a user into entering a code into a fake site. Passkeys and security keys can bind authentication to the legitimate service. Use supported methods appropriate to your organisation, and understand which weaker recovery paths remain available.
Treat unexpected prompts as evidence
Do not approve a push notification you did not initiate. Repeated prompts are not a reason to accept one. Report the time and account involved, then review the account through a known address. Keep recovery codes somewhere secure and separate from the device you might lose.
APPLIED EXAMPLE
Put it in context
A worker receives repeated sign-in prompts while away from their laptop. They deny the requests and report them. Approving one to stop the noise could authorise someone else’s session.
Illustrative scenario for learning, not a claim about a verified customer incident.Common mistakes
- Counting password plus PIN as independent factors
- Sharing one-time codes with “support”
- Ignoring recovery settings
Your practical checklist
Checklist ticks are temporary and are not recorded as account progress.
MINI RECAP
MFA is stronger when the method resists phishing and users understand the recovery and approval process.