By NHI Mgmt Group Editorial TeamBased on StrongDM: “5 Types of Multi-Factor Authentication (MFA) Explained” (June 25, 2025)

TL;DR: Passwords are no longer enough, and five MFA types show why stronger factors such as security keys, biometrics, and certificates materially reduce compromise risk, according to StrongDM. The harder question is governance: identity controls must match the actor, access duration, and operational risk, not just add another login step.


At a glance

What this is: This is a practical comparison of five MFA methods, with the central finding that weaker factors still leave password risk exposed while stronger factors materially improve resistance to compromise.

Why it matters: It matters because IAM and PAM teams have to align authentication strength with the sensitivity and duration of access, especially where privileged, temporary, or externally exposed accounts are in scope.

By the numbers:

  • The average data breach grew by 10% to $4.88 million in 2024, according to IBM.
  • Researchers at Microsoft found that MFA can safeguard user credentials by up to 98.56%.
  • Google research cited in the article found that SMS-based MFA blocked 70-100% of unauthorized login attempts, depending on attack type.

Context

Multi-factor authentication adds a second or third proof of identity, but the control only works when the factor matches the risk. Password-only access remains brittle because social engineering, brute force, and credential theft still succeed when organisations treat every login as equally sensitive.

The article frames MFA as a spectrum of assurance, from weaker channels such as SMS and email to stronger options such as security keys, biometrics, and digital certificates. For identity programmes, the practical question is not whether MFA exists, but whether the factor is strong enough for the account, workflow, and privilege level being protected.

That distinction matters across human IAM, PAM, and non-human access patterns because the same login control can carry very different assurance depending on who or what is authenticating and how long the access lasts.


Key questions

Q: When does weak MFA create more risk than it removes?

A: Weak MFA creates more risk when the chosen factor is easy to intercept, clone, or fatigue-approve, but the account protects sensitive data or administrative access. In those cases, the control can create a false sense of safety while leaving the most likely attack paths intact. Assurance must match the value and exposure of the account.

Q: Why do hardware security keys reduce phishing risk more effectively than codes sent by SMS or an authenticator app?

A: Hardware security keys bind authentication to a physical possession factor and only respond to legitimate websites and apps. That makes stolen codes far less useful to attackers, because the key will not authenticate against a fake destination. The result is stronger resistance to phishing, reduced reliance on copyable secrets, and better protection for sign-in flows that adversaries commonly target.

Q: What are the signs that authenticator-based MFA is failing?

A: Common signs include repeated approval prompts, users normalising unexpected notifications, and successful logins after no obvious credential reset or device change. Those symptoms indicate the control may be vulnerable to MFA fatigue or user confusion rather than true second-factor assurance. If users are conditioned to approve, the factor is acting more like friction than defence.

Q: Should organisations use digital certificates for temporary access instead of passwords?

A: Yes, when access must be time-bounded and revocable, certificates are stronger than passwords because they can expire and be revoked as part of a lifecycle. The trade-off is governance overhead: if expiry and revocation are not managed well, the assurance benefit disappears. They fit best where temporary access is high value and tightly administered.


Technical breakdown

Why MFA strength depends on the factor type

MFA is not a single control but a family of assurance methods built from different proof types: something you know, something you have, something you are, and context signals such as location or device. The technical difference is whether the attacker must defeat only a reusable secret or also a second possession or biometric check. Channels like SMS and email are easy to deploy but remain vulnerable to interception, SIM swapping, and phishing. Security keys and certificates raise the bar because the proof is bound to hardware or cryptographic material rather than a retrievable code.

Practical implication: Match the factor type to the threat model instead of treating every MFA deployment as equivalent.

Authenticator apps and the MFA fatigue problem

Authenticator apps often use time-based codes or push approval prompts, which improve on password-only access but still depend on a user responding correctly under pressure. The weakness is operational as much as technical: repeated prompts can condition users to approve requests reflexively, creating MFA fatigue. That makes the control susceptible to social engineering even when the underlying factor is stronger than SMS. Rolling codes reduce the chance of blind approval because the user must actively enter a changing code rather than tap a generic notification.

Practical implication: Prefer code-based or phishing-resistant flows where approval fatigue is a realistic abuse path.

Why certificates and security keys change access governance

Security keys and digital certificates are stronger because they bind authentication to possession of a physical token or a cryptographic credential with explicit validity boundaries. Certificates are especially useful when access should exist only for a defined period, such as contractors or temporary staff, because issuance and expiry create a built-in lifecycle. The governance challenge shifts from remembering to ask for MFA to managing issuance, revocation, replacement, and expiry with enough discipline that access does not outlive its approval.

Practical implication: Treat strong MFA as lifecycle-managed access, not just a login experience improvement.


Threat narrative

Attacker objective: The objective is to convert stolen passwords into durable account access that survives a single-factor compromise.

  1. Entry often begins with compromised usernames and passwords, then social engineering or brute force is used to reach the authentication step.
  2. Escalation follows when the weaker second factor is intercepted, cloned, fatigue-approved, or otherwise bypassed.
  3. Impact occurs when the attacker turns that authenticated session into account takeover, unauthorized access, or privileged reach into sensitive systems.
  • Uber breach 2022: A contractor's stolen password and MFA fatigue gave a Lapsus$-linked attacker Uber's internal tools; Uber rotated keys to many services.
  • Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Password-only access is no longer the baseline problem. The real governance problem is that many identity programmes still assume a password is the primary credential and MFA is an optional add-on. That assumption fails as soon as credential theft becomes the dominant breach path. The result is not just weaker login security, but a programme design that underestimates how often authentication itself is the attack surface.

Strong MFA is only strong when it is operationally governable. Security keys, biometrics, and certificates materially improve assurance, but each introduces lifecycle obligations that many teams underbuild. Lost keys, revoked contractors, expired certificates, and recovery flows all become identity governance events, not helpdesk side issues. The practitioner lesson is to design for issuance, revocation, and recovery as part of access policy.

Authentication strength should be selected by privilege, not by convenience. The article implicitly shows a split between low-risk consumer-style access and high-risk administrative or temporary access. That split maps cleanly to PAM thinking: the more sensitive the access path, the less defensible weak, easily phished, or fatigue-prone factors become. Teams should stop asking which MFA is easiest and start asking which factor is defensible for the account class involved.

Credential-bound access needs lifecycle control, not just step-up verification. Digital certificates work because they create time-bounded trust, but that also means organisations must manage renewal, expiry, and revocation with precision. This is where identity governance, PAM, and temporary access patterns converge. If the lifecycle is not controlled, the factor becomes a false signal of assurance rather than a real control.

Named concept: authentication assurance mismatch. The article shows a recurring pattern where the factor used to protect an account does not match the sensitivity of the access being granted. That mismatch creates a governance gap between login protection and real operational risk. Practitioners should treat assurance level as a policy decision, not a user preference.

From our research library:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

What this signals

Authentication assurance is now a governance decision. MFA selection is not just a technical hardening choice, because the control surface changes with privilege, duration, and user behaviour. When organisations apply the same factor to every account, they usually optimise for ease of rollout rather than resilience.

Temporary access pushes teams toward lifecycle-aware authentication. Certificates and other stronger factors only work cleanly when issuance, expiry, and revocation are part of the operating model. That moves MFA into the same governance conversation as joiner-mover-leaver processes and privileged access management.

Weak factors remain acceptable only where the blast radius is small. SMS and email can still be pragmatic for low-risk access, but they should not be the default for sensitive systems or administrative use. The decision threshold should be impact, not habit.


For practitioners

  • Define MFA by account class Set different authentication requirements for standard users, privileged users, contractors, and externally exposed access paths instead of applying one MFA policy everywhere.
  • Prioritise phishing-resistant factors for high-risk access Use security keys or certificate-based authentication where takeover risk is highest, especially for admin consoles and sensitive internal systems.
  • Remove approval-based fatigue paths Replace push-only approvals with methods that force an explicit code entry or possession check so repeated prompts cannot be accepted reflexively.
  • Build certificate lifecycle governance Track certificate issuance, expiry, renewal, and revocation as part of identity governance for temporary workers and high-assurance access.

Key takeaways

  • Passwords still fail as the primary line of defence because attackers target the authentication process itself, not just the protected system.
  • The article’s examples show that MFA strength varies widely, with some methods resisting phishing and takeover far better than others.
  • Identity teams should align factor strength, access lifecycle, and privilege level so authentication policy reflects actual operational risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationThe article is fundamentally about authentication factor strength and assurance.
SP 800-63C — FederationCertificate and federated login patterns depend on identity federation and trust handling.
Recommendation — Use SP 800-63B to match authentication methods to the required assurance level for each account class. Align federated authentication flows with SP 800-63C where certificates or external identity providers are involved.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article ties MFA choice to access protection and authorization risk.
Recommendation — Apply PR.AA-05 to ensure access controls reflect the sensitivity of the protected resource.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe piece includes certificate-based and credential-based access patterns relevant to non-human authentication risks.
Recommendation — Review NHI authentication flows for weak second factors and replace them with stronger possession-based methods.
MITRE ATT&CKTA0006 — Credential AccessThe article centers on compromise paths that start with stolen credentials and second-factor bypass.
Recommendation — Map MFA gaps to credential access tactics and prioritise the most phishable login paths for hardening.

Key terms

  • Multi-Factor Authentication: Multi-factor authentication requires two or more independent verification factors before access is granted. In practice, it reduces the chance that a stolen password alone will open a system, but it only works well when applied consistently across all high-risk access paths and identity types.
  • MFA Fatigue: MFA fatigue is the behavioural pressure created when repeated login prompts make a person more likely to approve access without checking carefully. It is a control failure in the authentication experience, and it becomes dangerous when the approved session carries broad privilege or long-lived access.
  • Security key: A physical possession factor, usually a hardware token, that proves access by cryptographic challenge rather than by shared secret. It is especially useful for privileged access because remote attackers cannot complete the login without the device in hand.
  • Digital Certificate Authentication: An authentication approach that uses a certificate and private key pair to prove identity. It is often used for time-bound or higher-assurance access, but the control only works well when issuance, expiry, revocation, and replacement are governed as part of the identity lifecycle.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org