3 Identity and Authentication
Learn how digital identities, authentication factors, passwords, and multifactor sign-in work together to protect online accounts.
Identity, , and
A is the information a service associates with an account. An , such as a username or email address, helps name or locate that account. It does not prove that the person presenting it owns or controls the account.
checks whether someone controls an authenticator linked to the account. happens separately: it determines which actions the authenticated account may take. In short, checks control; sets permissions.
Three types of
fall into three categories:
Something you know: a password or PIN.
Something you have: a phone, security key, or other authenticator.
Something you are: a biometric characteristic, such as a fingerprint or face match.
Using two passwords still relies on one factor category: both are something you know. A biometric may unlock a device that activates an authenticator, but a biometric match alone is not necessarily a separate factor in an online sign-in.
Build safer password habits
A password is a secret used to authenticate. Attackers may guess common passwords, try passwords exposed in breaches on other services, or use phishing to trick people into revealing them. Reusing a password creates a risk: a password exposed at one site may be tried on other accounts, such as email.
Use a long, unique password for each account. A can create and store strong, distinct passwords, so you do not need to memorize them all. A memorable passphrase made of several words can also be effective. Length and uniqueness matter more than predictable substitutions, such as changing password to Password1!.
Do not change passwords on an arbitrary schedule just for the sake of changing them. Change one if it may have been exposed or compromised. Prioritize unique passwords for important accounts, especially email, banking, and accounts that can reset other passwords.
Add a second layer with MFA
requires more than one distinct type of factor. For example, a password plus a code from an authenticator app combines something known with something possessed. Asking for a second password does not provide a second factor because both passwords are things you know.
MFA makes account takeover harder if one factor is stolen, but methods vary in their resistance to scams. Passkeys and security keys use cryptographic designed to bind sign-in to the legitimate service, making them resistant to many phishing attacks. One-time codes and text-message codes add a check, but someone may still be tricked into sharing a code or approving an unexpected sign-in.
When available, prefer a passkey or security key. Otherwise, enable an MFA method offered by the service. Never share a sign-in code or approve a request you did not initiate.
Protect accounts and respond to suspicious activity
Reduce account risk by combining strong sign-in methods with careful account maintenance:
Visit services through a trusted app or by entering a known address. Be cautious of sign-in links in unexpected messages.
Secure the device or account used to receive prompts.
Review sign-in alerts, devices, and active sessions. Sign out unfamiliar sessions and change affected credentials.
Keep recovery options current. Store recovery codes somewhere secure and separate from the account they unlock.
If you suspect compromise, change the password from a trusted device, revoke unfamiliar sessions, and review recovery details and MFA methods.
Takeaway: Use a unique password for each important account, enable MFA, prefer when available, and keep recovery options secure.