Multi-factor authentication (**MFA**) requires a user to *verify their identity in two or more ways* to access a system or network. In a sense, MFA is similar to using an ATM to withdraw money from your bank account. First, you insert a debit card into the machine as one form of identification. Then, you enter your PIN number as a second form of identification. Combined, both steps, or factors, are used to verify your identity before authorising you to access the account. ### Strengthening authentication **MFA** builds on the benefits of **SSO**. It works by having users prove that they are who they claim to be. The user must provide two factors (2FA) or three factors (3FA) to authenticate their identification. The MFA process asks users to provide these proofs, such as: - *Something you know*: most commonly a username and password, PIN, or the answer to a security question - *Something you have*: Such as a smart card, USB or bluetooth token, or another object or item that is in your possession, like the Titan security key - *Something you are*: refers to physical characteristics of a user, like their fingerprints, retina scans, voice prints, end even the typing speed and patterns - *Somewhere you are*: Also known as location factor. GPS, network location, and other data can bed used to ensure that users who are in the location they should can authenticate Requiring multiple forms of identification is an effective security measure, especially in cloud environments. It can be difficult for businesses in the cloud to ensure that the users remotely accessing their systems are not threat actors. MFA can reduce the risk of authenticating the wrong users by requiring forms of identification that are difficult to imitate or