Does an email-based SSPR (self-service password reset) compromise the "possession" factor for MFA?

Viewed 10

I'm trying to implement a security policy with MFA. Currently, there is an email based SSPR (self-service password reset) available to users.

As far as I can tell from the following resources:

MFA authentication should require at least 2 different factors, most commonly knowledge and possession.

However, both the resources list email as "possession" or "something you own", so if a user can use this to reset their password, doesn't this mean that the "knowledge" factor can effectively be circumvented? Does this mean I am limited to biometrics or behavioral analysis, both of which are significantly more expensive to implement than, for example, a TOTP system?

0 Answers
Related