MFA and
account security
Why your sign-in asks twice, and how that one extra step stops someone who has stolen your password.
NT World Ink · Digital and AI Literacy
01 / 13A password is one key, and keys get copied
One password, many doors
When the same password unlocks your email, banking and streaming accounts, one leak opens all of them.
Tricked out of you
A convincing fake email or text can lead you to a fake sign-in page, and you type the password in yourself.
Stolen in bulk
Passwords stolen from websites are traded online in huge lists, often years after the original breach.
None of this needs a genius hacker. It just needs your password, and your password can travel without you.
02 / 13Ask for two different kinds of proof
Something you KNOW
A password or PIN. It lives in your head, but it can be guessed, stolen or tricked out of you.
Something you HAVE
Your phone with the Authenticator app. A thief on the other side of the world does not have it.
Something you ARE
Your fingerprint or face. It unlocks your phone, which protects the app inside it.
Multi-factor authentication (MFA) means two or more different types. Two passwords is still one type; a password plus your phone is two.
03 / 13Strong on its own? Never. Still worth doing well
Rooty2024!
Short, based on a word, follows a pattern attackers try first. The exclamation mark is not fooling anyone.
cyclone paddock lantern tide
A passphrase: four unrelated words. Long, easy for you to remember, very slow for software to guess.
04 / 13Your phone becomes the second lock
The Microsoft Authenticator app on your phone receives a notification whenever someone signs in with your password.
No mobile signal needed at the moment of sign-in on Wi-Fi; the push arrives over any internet connection your phone has.
Lost phone? Tell IT straight away; they can move MFA to a new device.
Outlook · Darwin, NT
05 / 13Your face or fingerprint guards the guard
You will mostly meet this factor when you unlock your phone. The fingerprint or face scan protects the Authenticator app sitting inside it.
06 / 13Your work sign-in, step by step
07 / 13Why type a number instead of tapping Approve?
The number appears only on the screen where the sign-in is happening. If that screen is not in front of you, you cannot approve, even by accident.
A plain Approve button can be tapped half-asleep. A number cannot be guessed into the app; it makes approval deliberate.
08 / 13They have your password.
The password works.
09 / 13The push goes to your phone, not theirs
Unknown location · 2:14 am
10 / 13A push you didn't ask for means someone has your password
11 / 13Four habits that do most of the work
Only approve sign-ins you started
If you are not looking at a sign-in screen right now, the answer is no.
Nobody legitimate asks you to approve
IT will never ring and ask you to approve a push or read out a code. Anyone who does is the attack.
Use a passphrase, used nowhere else
Four random words for your work account, different from every personal account.
Keep Authenticator on your phone
Do not delete it to save space; report a lost or new phone to IT promptly.
12 / 13What to take with you
A good next step: spotting scam emails, and where AI fits into everyday work.
13 / 13