How people prove who they are.
WHAT METHODS EXIST
Passwords Authenticator applications, producing codes or approving notifications Codes sent by message or call Hardware security keys Passkeys Certificates
WHAT TO PREFER
Methods resistant to interception and to being relayed by an attacker.
WHAT THOSE ARE
Security keys and passkeys, and authenticator approval with number matching.
WHAT TO AVOID WHERE POSSIBLE
Codes sent by message.
WHY
They can be intercepted or redirected, delivery is unreliable, and they cost money.
WHAT NUMBER MATCHING DOES
Requires the user to enter a number shown on the sign-in screen into the authenticator.
WHAT IT PREVENTS
Approval fatigue, where a user approves a repeated prompt they did not initiate.
WHAT TO REQUIRE
At least two registered methods per user.
WHY
Losing a phone otherwise requires administrator intervention every time.
WHAT TO CONFIGURE
Self-service password reset, with sufficient verification.
WHAT THAT REDUCES
Support volume, substantially.
WHAT TO ELIMINATE
Legacy protocols that cannot use additional factors.