Skip to content

Multi-factor authentication

Requiring something more than a password to log in: a code, a key, or an app.

The case for it

What you lose without multi-factor authentication.

Stolen passwords are still the most common way a business gets compromised. Multi-factor authentication (MFA) makes an attacker produce something they can't type into a fake login page. It is the highest-impact control on this list, and the one most businesses only half finish. Half-finished MFA leaves the confidence without the protection.

Where you need to be

What each maturity level asks of multi-factor authentication.

The Australian Cyber Security Centre (ACSC) sets a requirement for this control at each maturity level, ML1 through ML3. Your overall Essential Eight score is your weakest control rather than an average, so a gap here pulls the whole score down.

ML1 The 2026 baseline

MFA is applied to internet-facing services, to cloud services that store sensitive data, and to privileged users. Phishing-resistant methods are used where possible.

ML2 Regulated or audited

MFA is applied to all users accessing important data. MFA uses phish-resistant methods (FIDO2 keys, certificates, or equivalent). MFA events are logged.

ML3 Defence or sensitive

MFA is phishing-resistant for all users accessing important data. MFA logs are monitored centrally. The second factor cannot be used in isolation.

Not sure which level you should aim for?

Three questions about your regulatory position and the data you keep will point you at the right target.

Take the maturity picker

The rollout

Setting up multi-factor authentication in your environment.

You get the strongest methods first: Microsoft Authenticator with number matching for staff, and a physical security key for admin accounts. Text-message codes are switched off, because a criminal can take over the mobile number they go to. Microsoft Conditional Access then asks for a second factor whenever someone signs in from an unmanaged device or an unusual location. Every prompt is logged, and a run of failed ones is treated as a detection signal, not a support ticket.

Free self-assessment

No email required.

Score yourself on all eight controls.

Eight questions, your estimated Essential Eight maturity level, and a branded PDF report you can share with your board, insurer, broker or auditor. Runs entirely in your browser. Nothing is sent to us unless you choose to book a call.

Take the self-assessment

Asked on client calls

Questions we get about multi-factor authentication.

We already have MFA on email. Isn't that enough?
What about SMS codes? Those are still common.
Our staff hate MFA prompts. What can you do?
What happens if someone loses their MFA device?

The maturity level summaries on this page are a plain-English version of the ACSC's published Essential Eight Maturity Model. For the full text, see the ACSC Essential Eight Maturity Model .

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit