Authentication methods: choosing the right type

Document preview8 pages
Cover of Authentication methods: choosing the right type
Page 1 of 8

Download this document free

Get this document with your free trial. Choose from the full Complyzard library.

Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.
Document information

Advice for retail and hospitality businesses or utility services needing to authenticate customers when accessing online apps or websites.

Adapted edition

Document type
Reference Guide
Format
DOCX
Pages
8
Language
English
Version
1.0
Updated
2026-09-16
Description

Advice for retail and hospitality businesses or utility services needing to authenticate customers when accessing online apps or websites for organisational planning, review and training. NCSC guidance is advisory and should be applied to the organisation's own risks and obligations.

Contents
  • Why go 'beyond passwords'?
  • How does additional authentication help?
  • Note:
  • Chose the model that's right for you
  • Multi-factor authentication (MFA)
  • MFA: a typical scenario
  • Federated Single Sign-On (SSO) services
  • Implementing federated SSO
  • OpenID Connect: typical scenario
  • FIDO2
  • Implementing FIDO2
  • FIDO2: a typical scenario
  • Magic links and one time passwords (OTPs)
  • Implementing magic links
  • Magic links: a typical scenario
  • Source links
Source and licence
Authentication methods: choosing the right type

National Cyber Security Centre

AttributionNational Cyber Security Centre, “Authentication methods: choosing the right type” (21 September 2022), reused under the Open Government Licence v3.0.

ChangesAdapted 16 September 2026: converted the official HTML article into neutral text-only DOCX and PDF editions. Preserved article headings, paragraphs, lists and plain-text source-link destinations; normalized web whitespace and typographic punctuation; omitted site navigation, topic and download cards, images, logos, scripts, styles and page furniture.

Version history
  • v1.016/09/2026
Report this document