Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.2.2. Multifactor Authentication (MFA)

💡 First Principle: MFA requires proving your identity with two or more independent factors — something you know (password), something you have (a phone or security key), or something you are (biometrics) — so that compromising just one factor (like a leaked password) isn't enough on its own to get in.

The power of MFA comes specifically from factor independence: an attacker who phishes a password still doesn't have the physical security key or the fingerprint. Microsoft Entra ID can enforce MFA through security defaults (a simple, tenant-wide baseline for organizations without custom policies) or, more granularly, through Conditional Access policies (3.3.1) that require MFA only under specific conditions — like sign-in from an unfamiliar location.

⚠️ Exam Trap: Two passwords are not MFA — both are "something you know." True MFA requires factors from genuinely different categories.

Reflection Question: An attacker has phished a user's password. Under what circumstance would properly configured MFA still stop them from signing in?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications