IDENTITY SECURITY / FOR HUMANS Exit lesson
MFA 2 / 8

THE PASSWORD WAS CORRECT

The login can still be fraudulent.

Think about MFA from the attacker's side. They have your username. They have your password. Both are correct.

The login reaches one final step: approval required. At that moment, your phone becomes part of the security boundary. If you approve the request, the system may reasonably conclude that the login is legitimate.