# Multi-Factor Authentication Service

> URL: https://www.atlantic.net/managed-services/multi-factor-authentication/ | Updated: 2026-09-16

Verify every login to Linux SSH, Windows RDP, hosted applications, and cloud workloads with managed MFA, role-based policies, device health checks, and flexible second-factor methods.

- SOC 2 Type II Infrastructure
- HIPAA & HITECH Audited
- PCI DSS 4.0 Aligned
- Role-Based Access Policies

Supported Methods: 4

Server Access: SSH + RDP

### Multi-Factor Authentication Service

Verify and authenticate users' identities before granting access to your server environment. Atlantic.Net's Managed Multi-Factor Authentication Service is the easiest way for users to confirm who they are before being granted access to your Linux (SSH) and Windows (RDP) servers, hosted applications, and cloud workloads.

The service deploys, integrates, and operates inside Atlantic.Net's SOC 2 Type II, HIPAA, HITECH, and PCI DSS-aligned hosting infrastructure, so the same MFA controls protecting your servers can be cited in your audit documentation.

### What Is Multi-Factor Authentication (MFA)?

Multi-Factor Authentication requires two or more methods (also called factors) to verify your identity. Factors typically combine something you know – like a username and password – with something you have, such as a smartphone app that approves authentication requests, or something you are, such as a fingerprint or face scan.

You may also see MFA called Two-Factor Authentication (2FA) when only two factors are required. 2FA is a subset of MFA; the terms are used interchangeably in many products.

### Why Do I Need Multi-Factor Authentication?

Multi-Factor Authentication is one of the most effective controls against remote attacks such as phishing, social engineering, credential stuffing, and brute-force password attempts. By integrating MFA with your Linux and Windows servers, attackers cannot access your accounts without also possessing the physical device needed to complete the second factor – even if the password has been stolen.

### Did You Know?

- An employee or contractor is responsible for 2 out of 3 insider threat incidents.
- Negligence-based insider threats cost on average $3.8 million per year.
- 52% of users re-use the same password across multiple logins.
- Microsoft has reported that MFA blocks more than 99.9% of automated account-compromise attacks.

### How Does the Multi-Factor Authentication Service Work?

During login, a verification code or push approval is required in addition to the user's username and password. This adds a second layer of security to the account: even if a password is leaked or guessed, an attacker cannot complete the login without the second factor.

### Atlantic.Net's Managed Multi-Factor Authentication

Atlantic.Net's Managed MFA delivers multi-factor authentication as a convenient single sign-on experience. Once cleared, the user gains access to enterprise files and applications – both on-premises and in the cloud – under a single policy framework.

Beyond verifying user identity, the service inspects the health of each device. By checking for the presence of essential security controls and out-of-date software, it can block high-risk or potentially compromised machines from connecting in the first place. Administrators retain control to enforce stricter access policies, such as requiring up-to-date software before login, lowering the attack surface against your confidential data.

## Verification Methods

Verification can happen by text message, phone call, an authentication app on a smartphone, or a one-time bypass code. Authentication-app codes work even when the user's phone has no cell signal. Administrators can choose one or more of the methods below to verify their users.

### SMS Passcodes

A passcode sent to your phone via SMS. Simply enter the code into the login prompt.

### Phone Callbacks

Answer a phone call and press any key to complete the login process.

### TOTP Passcodes

Open an authentication app on your smartphone and enter the displayed code into the login prompt. These are known as time-based one-time passcodes (TOTP).

### Bypass Codes

Useful for lost devices or to provide single-event access for contractors.

## Managed Multi-Factor Authentication Features

Atlantic.Net's Managed MFA integrates with most on-premises and cloud applications, including Office 365, Salesforce, Box, Dropbox, Google Workspace, Slack, and DocuSign. SDKs and client libraries cover project management apps such as Confluence, Jira, Splunk, and Drupal, plus Python, Ruby, Classic ASP, and Java to extend MFA into custom applications.

### Easy Registration

Facilitate secure access and manage logins for thousands of users via bulk user import, self-enrollment, and advanced admin capabilities including APIs.

### Protected Logins

Choose from several MFA methods and set user access policies that match your organization's security needs.

### Policy Enforcement

Set up role-based, custom access policies built on parameters that fit your needs.

### Device Hygiene

Quickly identify unmanaged onsite and mobile devices and at-risk software.

### Endpoint Access

Analyze security insights to differentiate corporate from personal devices, and control which endpoints can access which applications.

### Attack Prevention

Identify and contain risky users by mapping software vulnerabilities on their devices via a phishing simulator.

### Endpoint Remediation

Automatically prompt users to update their own devices.

### App Protection

Protect your cloud apps with secure logins and control which internal apps can be accessed by remote users.

## How MFA Methods Compare

| Method | What the User Needs | Strength vs. Phishing | Works Offline | Best For |
| --- | --- | --- | --- | --- |
| Password only (single-factor) | Username + password | Weak – vulnerable to phishing, leaks, brute force | Yes | Legacy systems (not recommended) |
| SMS passcode | Phone with cell signal | Moderate – vulnerable to SIM-swap attacks | No | Consumer apps, low-risk accounts |
| Phone callback | Phone with cell signal | Moderate | No | Helpdesk, healthcare front desks |
| TOTP authenticator app | Smartphone with TOTP app | Strong | Yes | Enterprise standard for SSH/RDP/SSO |
| Push approval | Smartphone with MFA app | Strong – resistant to credential phishing | No (needs data) | Daily enterprise sign-ins |
| One-time bypass code | Pre-issued code | Single-use only | Yes | Lost devices, contractor access, break-glass |

Improve your security posture with multi-factor authentication. Atlantic.Net's experts can seamlessly implement MFA to protect your applications and servers. Contact us to harden your servers against unauthorized access. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net.

## Frequently Asked Questions About Multi-Factor Authentication

### What is multi-factor authentication (MFA)?

Multi-factor authentication is a login control that requires two or more independent factors to confirm a user's identity: something they know (password), something they have (phone, hardware token), or something they are (fingerprint, face). Even if one factor is stolen, an attacker cannot complete the login without the others.

### What is the difference between MFA and 2FA?

Two-Factor Authentication (2FA) is a specific case of MFA where exactly two factors are required – typically a password plus a one-time code or push approval. MFA is the broader term that covers two or more factors. Most products use the terms interchangeably.

### Which verification methods does Atlantic.Net's Managed MFA support?

SMS passcodes, phone callbacks, time-based one-time passcodes (TOTP) from an authenticator app, and one-time bypass codes for lost devices or single-event access. Push approval and additional methods are available through specific integrations on request.

### Does the service work for Linux SSH and Windows RDP?

Yes. Atlantic.Net's Managed MFA integrates with Linux SSH and Windows RDP so that every interactive login requires a second factor in addition to the user's password.

### Can users self-enroll, or does an admin have to register every user?

Both. Administrators can bulk-import users via CSV or API, and end users can self-enroll their own devices through a guided workflow. Role-based policies allow you to require self-enrollment by a specific deadline.

### What happens if a user loses their phone or authenticator device?

An administrator can issue a one-time bypass code to allow the user a single login without the lost factor. The user re-enrolls a new device inside that session, and the bypass code is invalidated. Lost-device workflows are part of the managed service and do not require a support ticket for routine cases.

### Is MFA required for HIPAA, PCI DSS, or SOC 2 compliance?

MFA is either explicitly required or strongly expected by all three. PCI DSS 4.0 requires MFA for all access into the cardholder data environment. HIPAA's Security Rule expects organizations to implement reasonable authentication controls, and MFA is the de-facto baseline for protecting ePHI. SOC 2 auditors look for MFA on administrative and remote access paths. Atlantic.Net's Managed MFA is delivered inside the same audited environment that backs our HIPAA-compliant and PCI-compliant hosting.

### How does MFA integrate with single sign-on (SSO)?

Once a user clears MFA, they receive a single-sign-on session that grants access to enterprise files and applications – both on-premises and in the cloud – without re-prompting for the second factor on every app. Session length and re-authentication intervals are policy-driven and tunable per role.

### Can I require MFA only for specific roles or sensitive systems?

Yes. Policies are role-based and resource-aware: you can require MFA on production servers and admin consoles while leaving low-risk internal applications under password-only login. Most regulated customers require MFA across the board.

### How is the Managed Multi-Factor Authentication Service priced?

Pricing is based on the number of users protected and the integrations required. Contact our sales team for a quote tailored to your environment.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.
