Skip to main content

2FA Authenticator

A 2FA authenticator is an authenticator used as one factor in a two-factor authentication process.

What is 2FA Authenticator?

A 2FA authenticator is an authenticator used as one factor in a two-factor authentication process. Some multi-factor authenticators combine possession with a local activation factor. A normal TOTP application is a single-factor OTP authenticator. TOTP is not phishing-resistant because a user can enter the code into a false verifier. Use WebAuthn or another phishing-resistant cryptographic method when the risk requires it.

Why it matters

A second, independent factor can stop an attacker who steals one credential. A phishing-resistant authenticator also stops a false verifier from replaying a captured code.

How it works

  1. The user enrolls authenticators that prove two distinct factor types, or enrolls one multi-factor authenticator.
  2. The verifier challenges the required authenticators and validates each response during the authentication event.
  3. The verifier creates a session at the achieved assurance level and applies its timeout and recovery rules.

Example

An employee enters a password and then uses a WebAuthn security key. The key signs a challenge for the real relying party, so a false site cannot reuse that response.

Pomerium boundary

Pomerium authenticates users through a configured OpenID Connect identity provider. Configure two-factor or phishing-resistant user authentication at that provider. Pomerium then uses the verified identity claims in route policy.

Limits and non-claims

  • Two factors are not phishing-resistant when both responses can be entered into a false verifier.
  • Weak account recovery can bypass strong authenticators.
  • Successful two-factor authentication does not authorize every resource or prove that the device is healthy.

Evaluation checklist

  • Do the authenticators prove distinct factor types, or can one compromise defeat both?
  • Which part of the ceremony resists phishing, relay, replay, and approval fatigue?
  • Can enrollment, recovery, fallback, or session theft bypass the required assurance?

Sources and further reading

Keep learning

Identity and Authentication

Security Keys

A security key is a roaming or dedicated hardware cryptographic authenticator, such as a USB, NFC, or Bluetooth key.

Learn this term
Identity and AuthenticationStandards and Protocols

WebAuthn

WebAuthn is a W3C API for creating and using public-key credentials scoped to a relying party.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo