SECURE SIGN-INntworld.ink
Information Security Awareness

MFA and
account security

Why your sign-in asks twice, and how that one extra step stops someone who has stolen your password.

NT World Ink · Digital and AI Literacy

Charles Darwin University — CDU TAFE, ICT, Cyber Security and Digital01 / 13
SECURE SIGN-INthe problem
The problem

A password is one key, and keys get copied

Reused

One password, many doors

When the same password unlocks your email, banking and streaming accounts, one leak opens all of them.

Phished

Tricked out of you

A convincing fake email or text can lead you to a fake sign-in page, and you type the password in yourself.

Breached

Stolen in bulk

Passwords stolen from websites are traded online in huge lists, often years after the original breach.

None of this needs a genius hacker. It just needs your password, and your password can travel without you.

CDU TAFE brand02 / 13
SECURE SIGN-INknow · have · are
The fix

Ask for two different kinds of proof

🔑
Factor 1

Something you KNOW

A password or PIN. It lives in your head, but it can be guessed, stolen or tricked out of you.

📱
Factor 2

Something you HAVE

Your phone with the Authenticator app. A thief on the other side of the world does not have it.

👤
Factor 3

Something you ARE

Your fingerprint or face. It unlocks your phone, which protects the app inside it.

Multi-factor authentication (MFA) means two or more different types. Two passwords is still one type; a password plus your phone is two.

CDU TAFE brand03 / 13
FACTOR 1 · KNOWpasswords and passphrases
Factor 1 · Something you know

Strong on its own? Never. Still worth doing well

Weak

Rooty2024!

Short, based on a word, follows a pattern attackers try first. The exclamation mark is not fooling anyone.

Strong

cyclone paddock lantern tide

A passphrase: four unrelated words. Long, easy for you to remember, very slow for software to guess.

Keep work and personal passwords separate. Your work password should not be used anywhere else, so a leak elsewhere never reaches your workplace.
CDU TAFE brand04 / 13
FACTOR 2 · HAVEMicrosoft Authenticator
Factor 2 · Something you have

Your phone becomes the second lock

The Microsoft Authenticator app on your phone receives a notification whenever someone signs in with your password.

No mobile signal needed at the moment of sign-in on Wi-Fi; the push arrives over any internet connection your phone has.

Lost phone? Tell IT straight away; they can move MFA to a new device.

Microsoft Authenticator
Approve sign-in?
Outlook · Darwin, NT
47
No, it's not meYes
CDU TAFE brand05 / 13
FACTOR 3 · AREbiometrics
Factor 3 · Something you are

Your face or fingerprint guards the guard

You will mostly meet this factor when you unlock your phone. The fingerprint or face scan protects the Authenticator app sitting inside it.

Stays on your device; your workplace never stores your fingerprint or face
Cannot be phished by email; there is nothing to type into a fake page
Means a stolen phone alone is still not enough to approve a sign-in
CDU TAFE brand06 / 13
SECURE SIGN-INyour work sign-in
Putting it together

Your work sign-in, step by step

1Enter your work email address on the Microsoft 365 sign-in pageSTART
2Enter your passwordKNOW
3The screen shows a two-digit number, and a notification lands on your phoneHAVE
4Type that number into Authenticator and confirm (unlocking your phone used your fingerprint or face)ARE
5You're in. Around ten extra seconds, once per day or less on a trusted deviceDONE
CDU TAFE brand07 / 13
NUMBER MATCHINGwhy the two digits matter
Number matching

Why type a number instead of tapping Approve?

The number appears only on the screen where the sign-in is happening. If that screen is not in front of you, you cannot approve, even by accident.

A plain Approve button can be tapped half-asleep. A number cannot be guessed into the app; it makes approval deliberate.

Microsoft Authenticator
Enter the number shown to sign in
29
No, it's not meYes
CDU TAFE brand08 / 13
ATTACK · PART 1someone has your password
Walkthrough · An attacker tries your account

They have your password.
The password works.

1A phishing email caught you months ago, or a website you used was breached. Your password is on a list being sold online
2The attacker types your email and password into your workplace sign-in page, from anywhere in the world
3The password is correct. With no MFA, they would now be reading your email, your files and everyone you deal with
Freeze the picture here. The first lock has already failed. Everything now depends on the second factor.
CDU TAFE brand09 / 13
ATTACK · PART 2stopped at the second factor
Walkthrough · The second factor holds

The push goes to your phone, not theirs

4The two-digit number appears on the attacker's screen, far away
5The notification lands on your phone. You did not start this sign-in, and you cannot see their number anyway
6You tap “No, it's not me.” The sign-in dies. The stolen password is now almost worthless
Blocked. One tap from you beat a working stolen password.
Microsoft Authenticator
Approve sign-in?
Unknown location · 2:14 am
??
No, it's not meYes
CDU TAFE brand10 / 13
IF IT HAPPENSa push you didn't ask for
If it happens to you

A push you didn't ask for means someone has your password

1Never approve it, even to make the notifications stop. Attackers sometimes send push after push hoping you will give in; denying costs you nothing
2Tap “No, it's not me” every time
3Change your password as soon as you can
4Tell IT. An unexpected push is a security incident worth reporting, not an embarrassment
CDU TAFE brand11 / 13
GOOD HABITSday to day
Day to day

Four habits that do most of the work

Habit 1

Only approve sign-ins you started

If you are not looking at a sign-in screen right now, the answer is no.

Habit 2

Nobody legitimate asks you to approve

IT will never ring and ask you to approve a push or read out a code. Anyone who does is the attack.

Habit 3

Use a passphrase, used nowhere else

Four random words for your work account, different from every personal account.

Habit 4

Keep Authenticator on your phone

Do not delete it to save space; report a lost or new phone to IT promptly.

CDU TAFE brand12 / 13
SIGNED IN ✓takeaways
Wrapping up

What to take with you

A password alone is one copyable key; MFA adds a second, different kind of lock
The two-digit number means only the person at the real sign-in screen can approve
A push you didn't ask for = stolen password: deny, change password, tell IT
Ten seconds of your day versus an attacker in your workplace systems is a good trade

A good next step: spotting scam emails, and where AI fits into everyday work.

CDU TAFE brand13 / 13