Adding an Extra Layer of Protection to Your Accounts

Strong, unique passwords are an important first line of defense when it comes to cybersecurity—but what happens if someone gets their hands on your password?

That’s where multifactor authentication (MFA) comes in. It’s one of the simple habits recommended through Stay Cyber SMART, North Dakota’s cybersecurity awareness campaign:

  • Set strong, unique passwords.
  • Make multifactor authentication a habit.
  • Avoid risky links, attachments, and senders.
  • Regularly update software and devices.
  • Take care with personal information.

What Is MFA?

In addition to your password, MFA adds another way to verify that you’re really you when signing in, making it much harder for someone else to access your account.

The additional verification factor may be:

  • Something You Know – Such as a personal identification number (PIN).
  • Something You Have – Such as your phone or a security key.
  • Something You Are – Such as a fingerprint or face scan.

For example, you might enter your password and then approve a notification on your phone. Or you might use a fingerprint or facial recognition to confirm your identity. That extra step can help protect your account even if your password is compromised.

Why Does MFA Matter?

Imagine a cybercriminal gets your password through phishing, a data breach, or other means. Without MFA, that password may be all they need.

But with MFA, they still need another way to verify their identity—and they’re stopped dead in their tracks. That’s why MFA is one of the most valuable tools in your cybersecurity toolbelt.

MFA is especially important as cyberattacks become more sophisticated. Artificial intelligence can make phishing messages and other scams harder to recognize, increasing the importance of defense‑in‑depth protections.

You’re Probably Already Using MFA

Did you know? MFA may already be part of your daily routine!

  • Banking: You enter your password and then enter a security code or approve a notification.
  • Email & Social Media: You sign in and confirm with a second step.
  • Work Systems: You may use an authentication app, security key, PIN, badge, or biometric scan.

If you’ve ever had to prove your identity in more than one way, you’ve already used MFA.

Make MFA a Habit

The best time to turn on MFA is before you need it. 

Turn It On Where You Can

Start with accounts that matter most, including:

  • Email
  • Banking and financial accounts
  • Social media
  • Cloud storage
  • Shopping accounts
  • Work systems
  • Accounts containing personal or sensitive information

If a service offers MFA, take advantage of it. Doing so is a simple step with long‑lasting impact.

Consider an Authenticator App

Authenticator apps, such as Microsoft Authenticator (our recommendation), can generate one‑time security codes or send notifications to help verify your identity. They can also provide stronger protection than text messages, which can be vulnerable to certain types of attacks.

Don’t Approve Unexpected Requests

If you receive an MFA notification or security code request you didn’t initiate, don’t approve it. An unexpected request may mean someone has your password.

Instead:

  1. Deny the request.
  2. Change your password immediately.
  3. Check the account for unauthorized activity.
  4. Report the incident if appropriate.

Never approve an MFA request simply because you keep receiving notifications. Repeated prompts can be an attempt to wear you down. Don’t give in!

Keep Your Verification Methods Secure

Your phone, security keys, and other authentication tools protect your identity. Treat them accordingly:

  • Keep your devices and apps updated.
  • Use a screen lock.
  • Never share authentication codes.
  • Protect security keys from loss or theft.


Small Steps Can Make a BIG Difference

Protecting your accounts doesn’t have to be complicated. Strong passwords help, but MFA adds extra sizzle to your security. 

So the next time you see the option to enable MFA, take a moment to turn it on.

Stay safe. Stay secure. And as always—Stay Cyber SMART.