Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

Evaluating the Effectiveness of Multi-Factor Authentication in Preventing Unauthorized Access to University Information Systems

Akpan Idongesit Ededet

Abstract

Universities increasingly rely on digital information systems to manage sensitive data, including student records, staff information, and financial transactions. This reliance has made these systems prime targets for unauthorized access and cyberattacks. Multi-Factor Authentication has emerged as a widely recommended security measure, combining multiple verification methods to enhance access control. Despite its growing adoption, limited empirical research exists on the real-world effectiveness of MFA within university environments, particularly in resource-constrained contexts. This study evaluates the effectiveness of MFA in preventing unauthorized access to university information systems. Using a mixed-methods approach, the research combines analysis of system logs and security incident reports with surveys and interviews of staff and students. The study assesses changes in access control incidents pre- and post-MFA implementation, examines user compliance and perceptions of usability, and identifies challenges associated with MFA deployment. Findings indicate that MFA significantly reduces unauthorized access attempts and improves overall system security. However, effectiveness is moderated by factors such as user resistance, technical integration challenges, and infrastructure limitations. Usability issues, cost constraints, and legacy system compatibility were also identified as key barriers to optimal MFA adoption. The study concludes that while MFA is a critical component of university cybersecurity, its success depends on complementary measures, including user education, adaptive policies, and robust system support. These findings provide practical insights for university administrators, IT professionals, and policymakers seeking to strengthen digital security and contribute to a broader understanding of MFA deployment in higher education institutions.

Keywords

Multi-Factor AuthenticationUniversity Information SystemsCybersecurityUnauthorized AccessUser Compliance

References

Abduhari, E. S., Shaik, T. C., Adidul, A. B., Ladja, J. H., Saliddin, E. S., Adin, A. J., ... Tahil, S. K. (2024). Access control mechanisms and their role in preventing unauthorized data access: A comparative analysis of RBAC, MFA, and strong passwords. Natural Sciences Engineering and Technology Journal, 5(1), 418–430. Adams, A., & Sasse, M. A. (1999). Users are not the enemy. Communications of the ACM, 42(12), 40–46. https://doi.org/10.1145/322796.322806 Afolalu, O., & Tsoeu, M. S. (2025). Cybersecurity in Higher Education Institutions: A Systematic Review of Emerging Trends, Challenges and Solutions. Future Internet, 17(12), 575. https://doi.org/10.3390/fi17120575 MDPI Alasmary, W., Alhaidari, F., Alharbi, F., & Alzahrani, A. (2019). Cybersecurity challenges in higher education institutions: A systematic review. Journal of Information Security and Applications, 47, 81–91. https://doi.org/10.1016/j.jisa.2019.03.007 Alotaibi, S., & Almagwashi, H. (2018). Multi-factor authentication: A survey. International Journal of Computer Science and Network Security, 18(9), 66–78. Apthorpe, N., Beavers, B., Shvartzshnaider, Y., & Frischmann, B. (2024). Measuring NIST authentication standards compliance by higher education institutions. arXiv. Beautement, A., Sasse, M. A., & Wonham, M. (2016). The compliance budget: Managing security behaviour in organisations. New Security Paradigms Workshop, 47–58. https://doi.org/10.1145/1143120.1143127 Bonneau, J., Herley, C., van Oorschot, P. C., & Stajano, F. (2012). The quest to replace passwords: A framework for comparative evaluation of web authentication schemes. IEEE Symposium on Security and Privacy, 553–567. https://doi.org/10.1109/SP.2012.44 Cahyanto, I., Madihah, H., Budiarso, I., Sutrisno, A., & Hidayat, T. (2025). Effectiveness of multifactor authentication technology for protecting student privacy: A systematic literature review. Edum Journal, 7(2), 253–269. Das, A., Kim, J., Borisov, N., & Caesar, M. (2018). The effectiveness of multi-factor authentication against real-world attacks. Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 82–96. https://doi.org/10.1145/3243734.3243810 Das, S., Wang, B., Tingle, Z., & Camp, L. J. (2019). Evaluating user perception of multi-factor authentication: A systematic review. arXiv. arXiv Das, S., Wang, B., Tingle, Z., & Camp, L. J. (2019). Evaluating user perception of multi-factor authentication: A systematic review. arXiv. Das, S., Wang, B., Tingle, Z., & Camp, L. J. (2019). Evaluating user perception of multi-factor authentication: A systematic review. arXiv. arXiv E-SPIN Group. (2024). Multifactor authentication: Strength security with benefits, challenges, and best practices. E-SPIN Group EDUCAUSE. (2023). 2023 EDUCAUSE Horizon report: Teaching and learning edition. EDUCAUSE. https://www.educause.edu Florencio, D., & Herley, C. (2007). A large-scale study of web password habits. Proceedings of the 16th International World Wide Web Conference, 657–666. Garfinkel, S., & Rosenberg, B. (2021). Password security in modern computing systems. Addison-Wesley. Gaw, S., Felten, E. W., & Fernandez-Kelly, P. (2006). Secrecy, flagging, and paranoia: Adoption criteria in password selection. Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, 591–600. https://doi.org/10.1145/1124772.1124861 Grassi, P. A., Garcia, M. E., & Fenton, J. L. (2017). Digital Identity Guidelines (NIST SP 800- 63B). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-63b ISACA. (2025). Industry news: 2025 will MFA redefine cyberdefense in the 21st century. ISACA Jain, A. K., Ross, A., & Nandakumar, K. (2011). Introduction to biometrics. Springer. Kasahara, Y., & Shimayoshi, T. (2025). Our design and implementation of multi-factor authentication deployment for Microsoft 365 in Kyushu University. Kyushu University Pure Portal. Kyushu University Pure Portal Site Meyer, L. A., Romero, S., Bertoli, G., Burt, T., Weinert, A., & Lavista Ferres, J. M. (2023). How effective is multifactor authentication at deterring cyberattacks? Microsoft Research. Nagpal, D. (2024). Breaking down barriers: Overcoming usability challenges in multi-factor authentication systems. Medium. Medium National Institute of Standards and Technology . (2022). Digital identity guidelines (Special Publication 800-63B). NIST. https://doi.org/10.6028/NIST.SP.800-63b National Institute of Standards and Technology. (2017). Digital identity guidelines (NIST SP 800-63-3). U.S. Department of Commerce. Natter, G. (2025). A unified multi-factor authentication strategy: Enhancing security in academic institutions with a case study of TU Wien. Technische Universität Wien. vr.tuwien.ac.at Omega Network Solutions. (2024). 10 surprising limitations of multi-factor authentication . PMC. (2023). BAuth-ZKP—A blockchain-based multi-factor authentication mechanism for securing smart cities. PMC. Renaud, K., Volkamer, M., & Renkema-Padmos, A. (2014). Why doesn’t Jane protect her privacy? Privacy Enhancing Technologies Symposium, 244–262. https://doi.org/10.1007/978-3-319-08506-7_13 Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust architecture (NIST SP 800-207). National Institute of Standards and Technology. Stallings, W. (2020). Cryptography and network security: Principles and practice (8th ed.). Pearson. Tetlay, A., Treharne, H., Ascroft, T., & Moschoyiannis, S. (2020). Lessons learnt from a 2FA roll out within a higher education organisation. arXiv. Verizon. (2024). 2024 data breach investigations report. Verizon Enterprise Solutions. https://www.verizon.com/business/resources/reports/dbir/ Weir, C. S., Douglas, G., Carruthers, M., & Jack, M. (2009). User perceptions of security, convenience and usability for e-banking authentication tokens. Computers & Security, 28(1–2), 47–62. https://doi.org/10.1016/j.cose.2008.09.008 Weir, M., Douglas, S., Carruthers, M., & Jack, M. (2020). User perceptions of security and usability of multi-factor authentication. International Journal of Human-Computer Studies, 135, 102–114. https://doi.org/10.1016/j.ijhcs.2019.102379 Whitman, M. E., & Mattord, H. J. (2021). Principles of information security (7th ed.). Cengage Learning.

More Articles from INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND MATHEMATICAL THEORY

Advances in Algorithmic Contract Scoring for Pre-Negotiation Yield Optimization and Risk Retention

Author: Ngozi Samuel Uzougbo, Michael Ominyi, Cyril Chimelie Anichukwueze, Blessing, Chika Jones

DevTest flow: Designing a Scalable Continuous Testing Pipeline for High-Velocity Software Delivery

Author: Lawal Ahmed Oladimeji, Achori Busayo, Akeju BusayoZainab, Saka Samson, Damilare, Mbah Demian Chidi, Runsewe Similoluwa Mayowa, Oladiti Luqman, Abiodun