What is 2FA Authenticator?
A 2FA authenticator is an authenticator used as one factor in a two-factor authentication process. Some multi-factor authenticators combine possession with a local activation factor. A normal TOTP application is a single-factor OTP authenticator. TOTP is not phishing-resistant because a user can enter the code into a false verifier. Use WebAuthn or another phishing-resistant cryptographic method when the risk requires it.
Why it matters
A second, independent factor can stop an attacker who steals one credential. A phishing-resistant authenticator also stops a false verifier from replaying a captured code.
How it works
- The user enrolls authenticators that prove two distinct factor types, or enrolls one multi-factor authenticator.
- The verifier challenges the required authenticators and validates each response during the authentication event.
- The verifier creates a session at the achieved assurance level and applies its timeout and recovery rules.
Example
An employee enters a password and then uses a WebAuthn security key. The key signs a challenge for the real relying party, so a false site cannot reuse that response.
Pomerium boundary
Pomerium authenticates users through a configured OpenID Connect identity provider. Configure two-factor or phishing-resistant user authentication at that provider. Pomerium then uses the verified identity claims in route policy.
Limits and non-claims
- Two factors are not phishing-resistant when both responses can be entered into a false verifier.
- Weak account recovery can bypass strong authenticators.
- Successful two-factor authentication does not authorize every resource or prove that the device is healthy.
Evaluation checklist
- Do the authenticators prove distinct factor types, or can one compromise defeat both?
- Which part of the ceremony resists phishing, relay, replay, and approval fatigue?
- Can enrollment, recovery, fallback, or session theft bypass the required assurance?
