MFA Guide
Understand multi-factor authentication and which type suits each account.
What it does
Explains what MFA (multi-factor authentication) is and walks through the common options so you can choose the strongest one available for each service.
Why it matters
MFA adds another verification step when you sign in, so a stolen password alone usually isn't enough for someone to get into your account.
MFA (multi-factor authentication) adds another verification step when you sign in, beyond just your password. Even if someone has your password, MFA usually stops them from getting in.
Authenticator apps
An app on your phone generates a new code every 30 seconds. Strong, works offline, and not vulnerable to SIM swaps.
Passkeys
A newer option that replaces passwords entirely for supported services, using your device's screen lock. Very strong and phishing-resistant.
Security keys
A physical device you plug in or tap to confirm sign-in. Very strong, often used by people who need the highest level of protection.
SMS verification
A code sent by text message. Better than no MFA at all, but weaker than the other options, since SMS can be intercepted through a SIM swap.
Cyber Conduct doesn't enable MFA on your behalf — this explains how and why to turn it on yourself, in each service's own settings.