Skip to main content

Security essentials

Multi-Factor Authentication

MFA asks for more than a password. It substantially reduces many account-takeover risks, but the method, enrolment and recovery route still need protection.

Plain-English guidance · Last reviewed 24 July 2026

On this page

The business case

Why it matters

Passwords can be phished, reused, guessed or exposed by another service. A separate factor can stop a stolen password from immediately becoming account control.

Not all MFA methods resist the same attacks. Security keys and passkeys can better resist fake sign-in pages, while approval prompts and codes still depend on the user noticing context and rejecting unexpected requests.

Know the exposure

Common risks

01

MFA fatigue

Repeated approval prompts may pressure a user to accept one they did not initiate.

02

Weak recovery

An attacker may bypass strong sign-in controls through an insecure recovery email, helpdesk process or exposed backup code.

03

Partial coverage

Protecting the CMS but not email, hosting, DNS or registrar accounts leaves powerful recovery and change routes exposed.

Investigate, do not ignore

Warning signs

  • Unexpected approval prompts, verification codes or enrolment notifications
  • MFA is optional for administrators or exceptions are not reviewed
  • One person’s lost phone would lock the business out of a critical service
  • Backup codes are stored openly or recovery goes to a personal email account
  • Legacy applications or service accounts bypass the normal sign-in policy

Reduce likelihood and impact

Practical steps

  1. 01

    Prioritise critical identities

    Start with email, password manager, registrar, DNS, hosting, finance and all website administrator accounts.

  2. 02

    Choose the strongest practical method

    Prefer phishing-resistant passkeys or security keys where supported, then authenticator methods; understand the limitations of SMS and prompts.

  3. 03

    Enrol safely

    Verify the correct service and device, record who enrolled and prevent unapproved factors from being added after account compromise.

  4. 04

    Protect recovery

    Keep backup methods restricted, test the recovery process and ensure more than one authorised person can recover a business-owned account.

  5. 05

    Respond to unexpected prompts

    Reject the request, report it and review account sessions and credentials rather than repeatedly dismissing it as an annoyance.

Defined website support

How AHANIX can help

AHANIX can help enable and document MFA for website, hosting, domain and related accounts where the provider supports it.

  • Identify the critical web accounts that need protection
  • Support provider-specific MFA enrolment and safer administrator access
  • Document business-owned recovery routes and web-account handover

Clear limits

What this cannot guarantee

  • MFA does not guarantee account security and may not stop session theft, malicious applications, unsafe recovery or an already compromised device.
  • AHANIX cannot override provider recovery decisions or guarantee continued access when credentials, factors and recovery information are lost.

Continue with existing resources

Relevant tools and guides

These links use existing AHANIX tools and guides for the next useful check or deeper explanation.

Common questions

Multi-factor authentication questions

Is SMS MFA better than no MFA?

It usually adds protection against password-only attacks, but phone-number takeover, message interception and phishing remain concerns. Use a stronger phishing-resistant method where the service supports one.

What is phishing-resistant MFA?

It uses cryptographic checks tied to the genuine service, as with suitable security keys and passkeys, so a fake site cannot simply relay a typed code.

Should every user have MFA?

Protect all accounts where the service supports it, prioritising email, administrators and access to sensitive or critical systems. Avoid permanent exceptions without a documented reason and compensating controls.

A scoped next step

Protect the accounts that control your website

AHANIX can help map web-related administrator accounts, enable available MFA and document a safer recovery route.

Review web account access

Continue in the Security Centre