Enable Multi-Factor Authentication (MFA)
It’s always good to have a backup plan, and that’s exactly what MFA is! While strong passwords are crucial to protecting your assets, it’s best to have another layer of protection in place. Enabling MFA on your accounts does this by requiring something more than just your password when you login. MFA is one of the most effective things you can do to protect your accounts, and most of the services you already use support it.
Prepwork
There are a few things worth understanding before you enable MFA, mainly what your options are and how to choose what makes sense for your situation.
The Different Types of MFA
When you log in with MFA enabled, you'll enter your password and then complete a second verification step. That step usually comes in one of three forms.
An authenticator app on your phone generates a short numeric code that refreshes every 30 seconds. When you log in, you open the app and enter the current code. Google Authenticator and Microsoft Authenticator are two common options. This is generally the most practical choice for most people since they’re free, work without cell service once set up, and provide strong protection.
A code sent by text message is simpler to set up and widely supported. When you log in, the service sends a one-time code to your phone number and you enter it to complete the login. It's not quite as secure as an authenticator app, but it's still significantly better than a password alone.
A physical security key is a small device, roughly the size of a USB drive, that you plug in or tap to your phone to verify your identity. YubiKey is a common brand. It's the most secure option available, though it does require keeping the device on you and having a plan in case it's lost.
Technical Requirements
Before enabling MFA, it's worth confirming a few things. A cellphone or tablet is required for app-based or text-based MFA. For text message codes specifically, you'll need cell service at the time of login. Authenticator apps generate their codes locally on the device, so they don't require a connection at the moment you log in - which can be useful in areas with spotty coverage.
The service you want to protect also has to support MFA. Most major platforms do, including email providers, banks, and farm management software. You can usually find the option under the account's security settings.
When to Use MFA
Turn it on wherever it's available. If you're deciding where to start, prioritize accounts where unauthorized access would cause the most damage, such as, your primary email account, online banking, farm management and precision ag platforms, and any accounts tied to operational data or business records. Your email is worth particular attention, since it's typically used to reset passwords, conduct business, and is tied to almost every other account you have.
Additional Information
What Happens When You Can't Access Your MFA?
Most services provide backup codes when you first set up MFA. These are one-time codes meant exactly for situations where you can't access your usual second factor, like if you lose your phone or switch numbers. Save them somewhere secure when you get them. Printing them out and storing them with your other important documents works well. If you're ever locked out without a backup, account recovery is possible but slow. Setting up your backups at the start saves a lot of hassle later.
How Do You Keep Your MFA Secure?
Keep your phone locked with a PIN, password, or biometric (face ID or fingerprint) lock. If anyone can pick up your phone and access it freely, they can access your MFA codes as well. Beyond that, no legitimate company will ever ask you to read back your MFA code over the phone or in a message. If someone asks for it, that's a red flag worth taking seriously.
Why Isn't a Password Enough?
Passwords can be exposed in ways that have nothing to do with anything you did wrong. A company you've done business with gets breached and your credentials are part of what's taken. Someone tricks you into entering your login on a convincing fake site. Automated tools run through common login combinations until one works.
Here's where MFA comes in handy. Say you use the same email and password for your farm supply account and your online banking. Well, if that farm supply retailer gets hacked. Then the attacker now has your credentials! What happens if they try them on your bank's website? Without MFA, they're in. With MFA enabled on your bank account, they hit a wall. They have your password but not your phone, so the login fails and you get an alert that someone just tried to access your account.