Skip to main content
Guidance

Multi-factor authentication for your corporate online services

Advice on implementing strong methods of MFA for accessing corporate online services.

Page 3 of 7

Recommended types of MFA

iStock.com/Abdul Basit Noohani

The previous examples illustrate that choosing the type of MFA to implement means balancing competing demands that sit within your organisation’s risk appetite. However, where possible you should adopt the type of MFA in the order presented below. The NCSC have chosen this order based on the strength of authentication provided, including the assurance, accessibility, and usability that they provide. For each one, we've also outlined scenarios where the method is particularly appropriate (or less appropriate):

  1. FIDO2 credentials (on trusted 'platform' devices or 'roaming' keys)
  2. Challenge-based authenticator apps
  3. App-based code generators
  4. Hardware-based code generators
  5. Message-based methods (email, SMS and call-based)





Reviewed

Version

2.0