

0 / 2 embers
0 / 3000 xp
click for more info
Complete a lesson to start your streak
click for more info
Still calibrating
click for more info
Not enough gems
Cost: 6 gems
1: Multi-Factor Authentication
incomplete
2: TOTP
incomplete
3: Hardware Tokens
incomplete
4: Passkeys
incomplete
5: Choosing an MFA Method
incomplete
6: Account Recovery
incomplete
Back
ctrl+,
Next
ctrl+.
This lesson's interactive features are locked, please to keep using them
The strongest multi-factor authentication method on paper isn't necessarily the right choice for every situation. You have to balance phishing resistance against device support, cost, user friction, and recovery. Some of the trade-offs are:
If multiple auth methods are enrolled for an account, its protection is ultimately determined by the easiest sign-in or recovery path that an attacker can exploit. If an account accepts TOTP as a fallback, an attacker can target that method, even if the user normally signs in with a passkey.