Skip to main content

Authentication methods: choosing the right type

Recommended authentication models for organisations looking to move 'beyond passwords'.

ArtemisDiana via Getty Images

This guidance helps organisations to select an appropriate method to authenticate their customers who are accessing online services. It's intended for retailers, hospitality providers and utility services, but can be used by any organisation that needs to authenticate customers when accessing online apps or websites. Adding any of the methods described here (that is, in addition to password authentication) will significantly increase the security of your customer accounts.

There are several authentication methods that provide security that goes 'beyond passwords'. This guidance summarises the benefits and limitations of each method, so you can choose the one that's most appropriate for your organisation - and your customers. It also provides links to more detailed NCSC guidance on each of the authentication methods.


Note:

When setting your organisation's password policy, please refer to the NCSC's guidance for system owners. It explains how you can implement technical measures to reduce the burden on customers, and implement policies which support the ways in which people naturally work.

Chose the model that's right for you

This guidance looks at four authentication models:

For each authentication method, you should consider both the security and usability of each one, and - most importantly - the profile of your customer base. For example, some customers may be reluctant to purchase additional devices in order to buy goods from your online store.

Although passwords have weaknesses, as a method of authentication it's both understood and accepted by most users. Whichever model of additional authentication you implement, you'll need to provide additional support for your users, during account setup and beyond.

You should offer a range of methods to ensure you appeal to as many of your users as possible. And offering these options during account setup provides an opportunity to explain the benefits of extra authentication, and how it works.


Note:

The most appropriate second factor to use during MFA implementation will depend on what services your organisation offers, and your customer profile. For example, using a PIN code sent via SMS is the most widespread and well-understood second factor, but is not the most secure option. Providing your users with a choice of second factors will ensure you cover the widest customer base. For more information about implementing MFA - including detailed guidance on choosing authentication factors - refer to the NCSC's guidance on Multi-factor authentication for online services.

You should not mandate use of a second factor every time an MFA-protected service is used, as this would soon be irritating for users. It should only be required for high-impact activities, such as:

  • transferring large amounts of money
  • changing passwords
  • changing account details (including updating/adding credit card details)

A second factor should also be required whenever suspicious account activity is detected, such as a sign-in from an unfamiliar device, or from a different part of the world than is normal for that user.

Note that introducing MFA to online services will mean you need to provide additional support for your users, both during account setup and in the longer term (including what to do if users lose access to the second factor). The NCSC has produced guidance that can help your users get to grips with MFA. You can adopt this guidance to include in your own support materials, if required.

The following table summarises the conditions when implementing MFA are likely to be appropriate.

MFA is likely to be appropriate when:MFA is less likely to be appropriate when:
Security is of a higher priority than user experience and throughput.User experience and throughput is a higher priority than security.
Your users are willing to provide an additional means of contact (phone or email).Your users don't want to have additional contact information associated with your website.
Your users are confident using mobile devices, and able to identify an unexpected or false request.Your users are not confident using mobile devices, and are unlikely to understand authentication messages.
You are able to provide a range of options for how a user can verify themselves. 

MFA: a typical scenario

You are a large online marketplace, with customers who buy and sell goods through your website. Due to the growth in password attacks (such as credential stuffing against many online platforms), you’d like to reassure your customers by adding extra security, so you decide to implement MFA on your accounts. You provide customers with a choice of factors; they can either use a code sent via SMS, or an authenticator app. Because you don’t want to overburden your customers, you only prompt them for the second factor when a new device or login location is detected.

A customer, Jean, sells hand-crafted items through your marketplace, and she's aware of phishing and credential theft affecting another online marketplace. Accounts have been taken over, and users have lost income and struggled to gain control of their accounts. Jean is concerned that she may be a victim of future attacks on your marketplace, and this could significantly harm her livelihood.

As part of the setup process for 2SV, you are able to reassure Jean that this extra measure will make it much less likely that her account will be vulnerable to these sorts of attacks.




Published

Reviewed

Version

2.0