
The access scope is established
Before a method is selected, in-scope applications, user roles and accessible data are identified. Sensitive accounts are reviewed separately so that verification can be aligned with each role’s responsibilities.
Usage conditions are assessed
Smartphone availability and connectivity are checked for mobile push. With TOTP, codes are generated offline after enrollment, although network access may still be required by the destination application. Carrier coverage and phone-number risks are considered for SMS and voice.
The selection is validated in a pilot
Enrollment, sign-in, device replacement and recovery are tested with a limited group. Findings are recorded and the selected method is reviewed before broader rollout. Verification is complemented by authorization controls; verified identity is not treated as permission for every operation.
How are methods compared?
Second-factor selection begins with an inventory of sensitive applications. Phone availability, network access, installation restrictions and recovery paths are recorded for each group. In an environment with unstable connectivity, dependency on message delivery is tested in practice. Support cost and device replacement are assessed alongside sign-in convenience; simple initial enrollment does not necessarily imply simple recovery.
Phishing resistance is evaluated separately
Under NIST guidance, use of a one-time password alone does not establish phishing resistance. For sensitive access, the protocol and binding of authentication to the intended service are therefore evaluated. Findings are recorded in the selection matrix and compared with the deployed solution’s documented capabilities. The MFA label alone does not establish a particular assurance level.
Reference and scope
This planning guide is applied in accordance with organizational policy and documented system capabilities.
NIST SP 800-63B-4 — Authentication and Authenticator Management