You may have noticed that recently a lot of your accounts are now requiring multiple methods of verifying your identity when you login. No longer do you just enter your username and password to get into your email, your cloud apps, or your accounting system. You now also need to input a short code that is texted to you, generated by an app, or emailed. In some cases, you might be getting verification phone calls, using a smart card, or entering biometric data like a fingerprint.
What is this? This is multi-factor authentication (MFA). MFA consist of three things that when combined verify someone’s identity. This is often summarized as “something you know, something you have, and something you are” (for example, a combination of username, password, tokens, and/or biometrics).
It may seem like a hassle, especially when you’re setting up these multiple verification methods, or if you need to run to find your cell phone for that text message code. MFA really is not convenient, especially if it’s poorly designed. But it’s making your accounts even securer by requiring multiple pieces of information or identification from you. This lessens the likelihood that someone will have all the pieces of data they need to hack an account.
A hacker may have your username and a list of your commonly used passwords, but if they don’t have the third or fourth verification steps, they’ll be stopped in their tracks. And this is a very good reason to not be afraid of using MFA!
MFA can stop many common brute force attacks and phishing attempts. All it takes is a hacker to compromise a single email account in your organization. Suddenly coworkers start receiving legitimate-looking emails from a person they trust asking for sensitive information. Then the entire organization can be compromised.
But by enabling MFA, email accounts on services like Office 365 are much more secure and difficult to hack. (In 2019, Microsoft started rolling out mandatory multi-factor authentication in Office 365 to certain organizations and partner accounts. They know how essential MFA is, and they’re going to make it a default.)
The reality is that many traditional cybersecurity measures can be compromised without MFA. Anti-virus software, firewalls, encryption tools, network monitoring solutions, and more can all be bypassed if hackers compromise them and gain credentials to privileged user accounts. MFA is a beautifully simple solution to lock down accounts even further. And it’s often not that hard to roll out either.
So what are some quick reasons why multi-factor authentication is so important?
Do you have questions about how to enable MFA for your network, apps, and services? Start today! You can contact one of OXEN’s experts by emailing us at hello@oxen.tech or calling 888.296.3619.[oxenRule side="left"][recent_posts style="default" category="all" columns="3" title_labels="true" order="DESC" orderby="date" posts_per_page="3"]