Authenticator apps
Google Authenticator, Microsoft Authenticator, Authy or 1Password: six digits that change every thirty seconds, computed on the phone itself with no need for coverage.
Multi-factor authentication
Google Authenticator, Microsoft Authenticator, SMS, WhatsApp, Telegram, email or passkey. Required by role rather than for everyone alike, and every sign-in is recorded with the factor that was used.
A leaked password stops being a serious problem the moment there is a second factor in the way. Multi-factor authentication combines proofs from different categories — something you know, something you have and something you are — and Kimobox delivers it through the channel each person already uses: an authenticator app, SMS, WhatsApp, Telegram, email or a passkey. It is required by role, with recovery codes and a record of every sign-in, because demanding it everywhere for everyone is the fastest way to get the code written down on a sticky note.
Google Authenticator, Microsoft Authenticator, Authy or 1Password: six digits that change every thirty seconds, computed on the phone itself with no need for coverage.
A one-time code through the channel the person already has open. Useful for shop, site or warehouse staff without a corporate mailbox.
The simplest way in: a code to the verified mailbox, with a short expiry and a single attempt per code.
WebAuthn sign-in with fingerprint, face or a physical key. There is no code to intercept and none to type.
Mandatory for administration and personal data, optional for read-only access. The policy is set per role, not person by person.
+ infoWho signed in, when, from where and with which factor. Failed attempts are kept too, which is where the problems show up.
+ infoWhere to require it
Real examples
Manufacturing · platform administration
Before A single shared administrator account kept in a password manager. When a setting changes, nobody can say who changed it, and one of those four leaving forces a password change for all of them.
After One user per person, with a mandatory second factor on the administration role. The log keeps the name, the time and the verification channel, and a leaver is handled by disabling one user.
Retail · staff without a corporate mailbox
Before A second factor by email reaches nobody: shop staff have no corporate account and use their personal phone to check the rota.
After A code by WhatsApp to the same number that already receives the rota, with no new app to install and no mailbox to create and then maintain.
Services · leaked credentials
Before Somebody signs in with the correct password from a country where the company does not operate. The access looks legitimate and is spotted weeks later, while reviewing a bulk document download.
After The attempt stops at the second factor, raises an alert to the account holder and the administrator, and stays in the failed-attempt log with its source address.
Vocabulary
Frequently asked questions
It means requiring two or more proofs of identity from different categories: something you know (a password), something you have (a phone, a key) and something you are (a fingerprint, a face). Two passwords in a row are not multi-factor, because both belong to the same category.
TOTP apps such as Google Authenticator or Microsoft Authenticator, a code by SMS, WhatsApp, Telegram or email, and passkeys or FIDO2 keys through WebAuthn. Each person can register more than one method and keep one as a fallback.
No Spanish rule demands it by that name for every company. Article 32 of the GDPR requires technical measures appropriate to the risk, and for remote access to personal data a second factor is now the standard measure. In the public sector, the Spanish National Security Framework strengthens the authentication mechanism according to the system's category, and ISO/IEC 27001:2022 covers it in control 8.5 on secure authentication.
Far better than no second factor, and worse than the rest. The NIST SP 800-63B guidance classes the telephone network as a restricted channel because of the risk of fraudulent SIM swapping and interception. It works as a way in or as a fallback; for accounts with broad permissions a TOTP app or a passkey is the better choice.
Enabling the second factor generates single-use recovery codes to be kept separately. If those are gone too, an administrator can reset the factor, and that reset is logged with its author and reason, because it is exactly the door an attacker would try.
TOTP apps do: the code is computed on the device from a shared key and the clock, as defined in RFC 6238, with no connection at all. SMS, WhatsApp, Telegram and email need a network.
Yes, and that is the advisable approach. Asking everyone for a second factor to check the holiday calendar breeds resentment and adds little; asking it of whoever manages users or downloads payslips does not.
The number the person registers to receive the code, for that purpose and no other. It is not used for marketing, it is not shared, and it is deleted when that verification method is removed.
Two-factor is the most common case of multi-factor authentication: exactly two. MFA is the general term, and it allows three or more when the risk justifies it.
We'll show you the module running with data similar to yours.
Keep exploring
Encryption, access control, an audit log, verified backups, and a data processing agreement that reads…
Access authorization to the plant or office per employee, with card, PIN or biometrics, automatically…
No clouds outside the European Union and no surprises in the data processing agreement. You know where your…
Asset inventory, risk analysis and Annex A controls, each with its status and owner.
Sources
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
Kimobox includes multi-factor authentication with time-based one-time password apps compatible with the TOTP standard — Google Authenticator, Microsoft Authenticator, Authy or 1Password — one-time codes by SMS, WhatsApp, Telegram and email, and passwordless sign-in through passkeys and FIDO2 security keys compliant with WebAuthn.
Two-step verification is configured per user role, with recovery codes, a fallback method, audited resets and a full log of sign-ins and failed attempts, in line with article 32 of the General Data Protection Regulation and control 8.5 of ISO/IEC 27001:2022.