Multi-factor authentication (MFA) is a system that increases account security by adding an extra security step when a user wants to access their account, requiring two or more types of authentication to prove the user's identity.
Why is it used?
Whenever a user wants to access an account on any platform, the user typically uses a combination of a username and a password. However, users may be at a greater risk of password compromise than they assume, especially if they reuse the same password on multiple websites. If the user's password is compromised, guessed or phished on a system containing sensitive information that does not support multi-factor authentication, an attacker who has the password can easily access, manipulate or delete sensitive information. Even downloading simple software or clicking links in emails can expose the user to password theft. The resulting damage can sometimes be irreversible.
With a multi-factor authentication mechanism, however, even if the password is compromised, an attacker will still need a second factor — making the stolen password useless by itself.
Differences between multi-factor authentication and two-factor authentication
When MFA is mentioned, 2FA comes to mind, and the two are often confused. MFA and 2FA basically perform the same operation: both increase account security by adding a security step. But there is a difference. MFA requires two or more types of authentication, while 2FA requires exactly two. We can call 2FA a subset of MFA.
MFA mechanisms in Monosign
-
Monosign Mobile Authenticator
Monosign Mobile Authenticator is a mobile application developed by Monofor, Inc.
How does it work?
When the user wants to log in to a system, it sends an instant notification to the user's mobile device and asks the user to prove that they are the right person. If the user taps the confirm button when the notification is received on their mobile device, the user successfully logs into the system. If the user thinks that the login attempt was not made by them, they can cancel the login process by tapping the reject button. The Monosign Mobile Authenticator application also generates a 6-digit one-time password every 30 seconds. Fingerprint or face recognition, which only the user possesses, can also be added to the Monosign Mobile Authenticator application. If the user wishes, they can log into the system using the code that is renewed on the mobile authenticator application.
-
Third-party mobile authenticators (MonoTP, Google Authenticator, Microsoft Authenticator, ...)
Third-party mobile authenticators are authenticator applications developed by other organizations.
How does it work?
Third-party mobile authenticators work like the Monosign Mobile Authenticator app. They also generate a 6-digit code every 30 seconds. The user enters the 6-digit code while logging into the system and the verification process is completed.
-
Text message (SMS)
When a user wants to log in to the system, an SMS is sent to the phone number registered in the system for that user. The user enters the 6-digit code sent via SMS while logging in and the verification process is completed.
-
Phone call
When a user wants to log in to the system, a phone call is made to the phone number registered in the system for that user. The user performs the verification by following the step specified in the phone call and logs into the system.
-
Security key
A physical security key is a small device that typically works with your USB port. It allows you to securely perform a secondary verification. Anyone who does not have this security key will not be able to access the user account or act on behalf of the user. Modern security keys implement the FIDO2/WebAuthn standards, and together with passkeys they are widely regarded as the most phishing-resistant authentication factors available today.
-
Personal e-mail
The personal email verification feature sends a verification code to a second email address the user trusts. Since this code will only be sent to an email address that the user trusts, those who do not have access to this email address will not be able to log into the user account.
MFA definitions and usage in Monosign
MFA definitions
If no MFA definition has been made in Monosign before, users can log in to the system with their user credentials.
After logging into the system, click on the user picture at the top right, then click on the "My Account" tab from the menu that appears.
Click on the "Multi-Factor Security" section on the screen you are directed to, and click on the "Activate" button at the top right (since MFA has not been activated yet). The MFA definition will then be made in Monosign for the user.
After MFA is activated, click on the "Use" section to use the Mobile Authenticator.
A QR code appears, which must be scanned from the mobile application. Open the Monosign mobile MFA application downloaded to the mobile device and tap the "Scan Barcode" section. Scan the QR code shown in the Monosign application on the website using the QR code reading screen, and Mobile Authentication is defined for the user's account.
When the user is directed back to the Multi-Factor Authentication page, it will show that the Mobile Authentication mechanism is active.
If the user wishes, they can define other MFA mechanisms in the system in the same way.
MFA usage
If an MFA definition has been made in Monosign before, the user logs in with their credentials. After logging in, the security step screen will appear.
When the user encounters this screen, they receive a notification from the mobile authenticator application. The user may approve or reject the login to the account by pressing and holding the incoming notification. If the user wishes, by tapping the notification, they can be directed to the application and perform the approval from within the application.
If the user has a problem receiving notifications while trying to log in to their account (for example, if the device settings do not authorize the application to send notifications), the user can click "To write 6 digit codes manually click here" when the security step screen appears. By opening the verification application on their mobile device, they can complete the verification by entering the 6-digit code, which is renewed every 30 seconds.
In addition, a user-specific PIN, face recognition or fingerprint reading can be defined in the mobile authentication application on mobile devices. Whenever the user wants to open the application, they can log into the mobile application using any of these features.
MFA advantages and disadvantages
Advantages
-
Security:
The primary benefit of multi-factor authentication is that it adds additional layers of protection. The more factors in place, the lower the risk of an attacker accessing critical systems and data.
-
Compliance and legal risks:
In addition to data encryption, regulators in many countries require certain businesses to apply multi-factor authentication in their standard operating procedures at the end-user level.
-
Easier login process:
Many unregulated businesses resist MFA practices, fearing a more complex login process for employees and customers. However, this extra layer of security allows organizations to redefine and redesign their login processes towards enhanced security.
-
Identifying security expectations:
Identifying security requirements and expectations in your organization is an essential part of any MFA implementation. For example, your industry, your business model, applicable compliance regulations (if any), and the type of data you capture, use and store to run normal business operations are important considerations. An MFA implementation is an opportunity to define and classify common business scenarios for each organization based on risk level and to determine when an MFA step is required.
Disadvantages
-
Blocked access:
Access to a specific application or system cannot be granted if you do not have access to one of your multi-factor authentication methods and you have not set up backup methods to verify user access.
-
Cost:
Traditionally, MFA can be costly if an organization uses a solution that requires on-premises hardware and must be integrated with existing identity solutions.
-
Login time:
The time required to log in to your system and verify using a mobile device may increase the login time.



