Not all types of MFA are created equal...
Our updated multi-factor authentication (MFA) guidance recommends organisations use techniques that give better protection against phishing attacks.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

For many years we’ve been enthusiastic advocates for multi-factor authentication (MFA). MFA – which can also be called 2-step verification (2SV) or two-factor authentication (2FA) – protects against many common attacks directed at user accounts. It’s why our guidance from 2018 came with the blunt message that organisations needed to start implementing 2FA on the parts of their corporate IT that are accessible from the internet.
At the time, a lot of organisations were moving their corporate digital services to the cloud. As they did this, those services became more exposed to attacks via the internet. In making that move, the NCSC emphasised that organisation’s authentication methods needed to be made more robust by including MFA.
MFA still makes a big difference compared with relying solely on passwords for authentication. Some recent high-profile breaches of corporate data (including one that impacted Ticketmaster, Santander and other Snowflake customers) would probably not have occurred if mandatory MFA had been enforced.
However, attackers have realised that many of the same social engineering techniques that tricked us into handing over passwords can also be updated to overcome some methods of MFA. We’ve seen the success of attacks against MFA-protected accounts increasing over the past couple of years, something which Mandiant also reflect on in their M-Trends 2024 Special Report.
It’s why we say that authenticating users to cloud-based corporate services using a password alone is not strong enough to protect any sensitive data. Accordingly, we’ve published a new version of our MFA guidance, which explains the strengths and weaknesses of the different ways of implementing MFA. This aims to help you choose the strongest type of MFA that is practical for your organisation.
The new guidance explains the benefits that come with strong authentication, while also minimising the friction that some users associate with MFA. Part of this involves only prompting for authentication or MFA when it makes a difference. Most organisations will have people in different roles, different ways of working, all using different types of devices. So we include options to help things work better for everyone.
As an example, the NCSC requires phishing-resistant MFA when I authenticate against our corporate single sign-on service. However, it’s exceedingly rare I get prompted for that because my MDM-managed phone and laptop act as strong phishing-resistant MFA factors themselves. It means that I only get prompted when I use a new device, or if the system identifies something suspicious about my account, my devices, or how I’m accessing apps. This means that the NCSC gets the protections that we associate with MFA, without burdening me with prompts that can induce security fatigue.
By adding more options, there’s always a risk that organisations adopt an approach that leaves them with a worse security posture. We’ve therefore taken the opportunity to also share some MFA anti-patterns that we’ve come across in recent years. By calling them out and explaining why they’re problematic, we’re hoping that you can avoid falling into the same traps. We’ve also added advice specifically for organisations that need to protect access to sensitive data, and recommended types of MFA for protecting administrative privileges.
We expect authentication will be front and centre of attackers’ targets for the foreseeable future. For security professionals, there’s a balance between a system that needs to be able to let legitimate users in, while also keeping illegitimate users out. Modern approaches can help us here: zero trust architectures, for example, can introduce extra defence-in-depth by making more nuanced authorisation decisions based on a range of signals. A push towards single sign-on and stronger authentication mechanisms (such as some password-less ones) will also help.
However, this modernisation can add complexity, and it will need adjusting over time as our adversaries learn the art of the possible. In the meantime we should be taking advantage of the promised benefits of the cloud by relying on providers to enforce robust standards.
In the near-term you should be looking for a service that – by default – uses phishing-resistant MFA for users.
The online services that make it easy for your users to adopt phishing-resistant MFA now are likely to be the same ones that will make it easy to transition to even more robust authentication and authorisation mechanisms in the future.
Andrew A
Cloud Security Research Lead


