MFA Setup & Best Practices

MFA Setup & Best Practices

Set up multi-factor authentication the right way.

What Is MFA Setup & Best Practices?

Enabling MFA is not one decision. It is a choice between methods that differ a lot in strength. You'll set up MFA on a corporate account and compare SMS codes, authenticator apps, and hardware keys, including a demonstration of how SIM swapping and real-time phishing proxies defeat SMS. Then a push notification you never requested arrives, and you'll practise the right answer: deny, change the password, report. The exercise closes on where to keep backup codes so a lost phone is not a lockout.

What You'll Learn in MFA Setup & Best Practices

MFA Setup & Best Practices — Training Steps

  1. Welcome to Valcrest Financial Services

    Today, IT Security has announced a company-wide initiative requiring all employees to enable multi-factor authentication (MFA) on their accounts. This training will guide you through setting up MFA and understanding best practices.

  2. Why Passwords Aren't Enough

    Every year, billions of passwords are stolen in data breaches. Even strong passwords can be compromised through phishing, keyloggers, or credential stuffing attacks. MFA adds a second layer of security. Even if someone steals your password, they cannot access your account without your second factor - something only you have.

  3. The MFA Initiative Email

    Alice receives an email from IT Security about the new MFA requirement.

  4. Accessing the Security Portal

    Alice clicks the link to access the Security Portal. This portal allows employees to manage their security settings, including MFA enrollment.

  5. Logging In to the Security Portal

    The Security Portal login page appears. Alice can use her password manager to securely fill in her credentials.

  6. Understanding MFA Factors

    The Security Portal displays an overview of multi-factor authentication. MFA requires two or more of these three factor types: Something You Know - Passwords, PINs, security questions Something You Have - Phone, security key, smart card Something You Are - Fingerprint, face recognition, voice Combining factors from different categories makes accounts much harder to compromise.

  7. Viewing MFA Options

    Now that you understand the three factor categories, let's explore the specific MFA options available at Valcrest Financial Services.

  8. MFA Options: SMS Codes

    The portal shows three MFA options. The first is SMS verification: SMS Text Messages A code is sent to your phone via text Easy to set up - just need your phone number Works on any phone that receives texts Limitations: Vulnerable to SIM swapping attacks Can be intercepted if phone is compromised Requires cell service SMS is better than no MFA, but not the most secure option.

  9. MFA Options: Authenticator Apps

    The second option is authenticator apps: Authenticator Apps (Google Authenticator, Microsoft Authenticator, Authy) Generate time-based one-time passwords (TOTP) Work offline - no cell service needed More secure than SMS - cannot be SIM swapped Codes regenerate every 30 seconds Considerations: Requires installing an app Must back up recovery codes - losing your phone means losing access Authenticator apps are recommended for most users.

  10. MFA Options: Hardware Security Keys

    The third and most secure option is hardware security keys: Hardware Security Keys (YubiKey, Google Titan, Feitian) Physical device you plug in or tap to authenticate Phishing-resistant - only works on legitimate sites Cannot be remotely intercepted Most secure option available Considerations: Requires purchasing a physical key Need a backup key in case of loss Not supported by all services Security keys are ideal for high-value accounts like financial systems.

Security Framework Coverage

MITRE ATT&CK

  • T1621 Multi-Factor Authentication Request Generation

CIS Controls

  • CIS 6 Access Control Management
  • CIS 14.3 Train Workforce Members on Authentication Best Practices

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • PR.AA Identity Management, Authentication, and Access Control