I'm trying to implement a security policy with MFA. Currently, there is an email based SSPR (self-service password reset) available to users.
As far as I can tell from the following resources:
- https://cheatsheetseries.owasp.org/cheatsheet/Multifactor_Authentication_Cheat_Sheet.html#resetting-mfa
- https://www.onelogin.com/learn/what-is-mfa
MFA authentication should require at least 2 different factors, most commonly knowledge and possession.
However, both the resources list email as "possession" or "something you own", so if a user can use this to reset their password, doesn't this mean that the "knowledge" factor can effectively be circumvented? Does this mean I am limited to biometrics or behavioral analysis, both of which are significantly more expensive to implement than, for example, a TOTP system?