Fingerprint or facial scan
The factor is the person, checked at the moment of authentication rather than inferred from possession of a device.
A fingerprint or facial scan verifies the person in real time — not the device, and not something they can hand over.
Most second factors verify possession of a device or receipt of a code, both of which can be intercepted, forwarded or socially engineered. Biometric MFA requires a fingerprint or facial scan to verify the user in real time, so even if a device or password is compromised, an attacker cannot complete authentication without the authorised individual’s own biological traits.
The mechanics behind the capability — what the platform does, and where it does it.
The factor is the person, checked at the moment of authentication rather than inferred from possession of a device.
Access still requires the authorised individual’s biological traits, so a stolen or malware-infected device is not sufficient.
Removes one-time passwords sent over the mobile network, and the SIM-swap and interception routes that come with them.
A scan is quicker than typing a code from another device, so the stronger factor is also the more convenient one.
Who feels the difference once Biometric MFA is in place, and how.
Security
A captured password cannot be replayed, because the factor cannot be captured or forwarded.
IT operations
Removes the cost, latency and delivery failures that come with one-time passwords over SMS.
End users
A scan replaces the code-hunting cycle across two devices, which is the part users resent most.
Audit
Authentication is bound to an individual rather than a shared device, which makes attribution defensible.
It works because the other capabilities share the same identity fabric. The quickest way to judge that is to watch it run against your own use cases.