▶ Stepthrough Courses All tutorials Blog Glossary Prompts Videos Visual guides Cheat sheets Comparisons Start Learning Free

What is multi-factor authentication (MFA)?

Quick answer

Multi-factor authentication, or MFA, means a login needs two or more different kinds of proof: something you know, like a password, plus something you have, like a phone app or security key, or something you are, like a fingerprint. Two-factor authentication, or 2FA, is the two-proof version.

Last updated

Updated · By Robert Breen

Why it matters for a small business

Passwords get stolen all the time, through reused passwords, data breaches and phishing emails that copy a real login page. MFA means a stolen password alone is usually not enough. The attacker also needs your phone, your key or your face, which is much harder to get from far away.

Not all second factors are equal. An authenticator app or a physical security key is generally stronger than a code sent by text message, because text codes can be intercepted or redirected. Passkeys, which use your device's lock screen, are another option many services now offer. Whatever you choose, save the backup codes somewhere safe, because losing your only second factor can lock you out of your own account.

In a real lesson: Build an AI Agent That Categorizes Business Expenses

In the AI Expense Categorizer Agent lesson, you build an n8n agent for Maple Street Bookkeeping, a made-up bookkeeping firm, that sorts expenses like a $45.00 CloudLedger charge for "monthly accounting software" and saves them to a sheet. The lesson does not cover MFA, but count the accounts it asks you to create or connect.

There is an n8n account, which emails you a code and then asks for a password. There is an OpenAI developer account where, as the lesson says, "in your own account it asks for a card at this point," plus an API key. And there is a Google credential, saved as Maple Street Google, that lets the agent write to your spreadsheets. Each one is a door into money or client records.

Turning on MFA for each of those accounts, where the service offers it, is a few minutes of work. An API key is different: it is a password for software and has no second factor, so the protection there is keeping it secret, giving it a clear name and deleting it if it leaks.

n8n AI Agent node with a system message written for Maple Street Bookkeeping
n8n AI Agent node with a system message written for Maple Street Bookkeeping

Try this lesson free or read the step-by-step guide.

Common confusions

MFA vs two-step verification

Services use both names. Strictly, a password plus an emailed code is two steps but arguably one factor if your email shares the same password. Treat the label as marketing and look at what the second step really is.

MFA vs single sign-on

Single sign-on reduces how many logins you have. MFA makes each login harder to fake. They work best together: one strong work login, protected by a second factor.

Tips

  • Start with the accounts that can spend money or read client data: email, accounting, payment and AI developer accounts.
  • Prefer an authenticator app or security key over text messages when the service offers a choice.
  • Never approve a login prompt you did not start. Repeated surprise prompts mean someone has your password, so change it.
  • Store backup codes somewhere other than the phone that holds your authenticator.

More Business terms

Where you use it: free lessons

Frequently asked questions

Is a text message code good enough?
It is much better than a password alone. An authenticator app, passkey or security key is generally stronger, so use one of those for important work accounts when the service supports it, and follow your company's policy.
Does MFA protect API keys and automations?
No. MFA protects people logging in. API keys and saved credentials let software act without a login prompt, so protect them by limiting who can see them, naming them clearly and revoking any that leak.

All AI glossary terms, A to Z · Free prompt templates