Definition
MFA is the broader term for authentication combining knowledge, possession or inherence factors. Two-factor authentication is a form of MFA, not an unrelated technology. A password plus a hardware security key can satisfy two categories; two knowledge questions do not become two factors merely because they are separate questions. The strength of the combination depends on implementation.
How It Works
A service may require multiple factors at login, when adding a withdrawal address or before other sensitive actions. One authenticator can also implement multiple factors, such as a device-held cryptographic credential unlocked by a local biometric. The service must verify the required combination and manage enrollment, replacement and recovery. Not every biometric unlock shown by an app necessarily proves that the server enforces MFA.
Key Considerations
Recovery procedures can become a weaker alternative entry point, so evaluate them alongside normal login protection. Keep recovery material secure and maintain a way to remove lost authenticators. Attackers may still steal active sessions, trick users into approving prompts or exploit poorly protected recovery channels. Phishing-resistant methods reduce some of these risks but do not eliminate every attack. For crypto holders, MFA protects supported accounts and actions; it cannot replace secure custody of private keys or prevent losses from every authorized on-chain transaction.