MFA is applied to internet-facing services, to cloud services that store sensitive data, and to privileged users. Phishing-resistant methods are used where possible.
Multi-factor authentication
Requiring something more than a password to log in: a code, a key, or an app.
The case for it
What you lose without multi-factor authentication.
Stolen passwords are still the most common way a business gets compromised. Multi-factor authentication (MFA) makes an attacker produce something they can't type into a fake login page. It is the highest-impact control on this list, and the one most businesses only half finish. Half-finished MFA leaves the confidence without the protection.
Where you need to be
What each maturity level asks of multi-factor authentication.
The Australian Cyber Security Centre (ACSC) sets a requirement for this control at each maturity level, ML1 through ML3. Your overall Essential Eight score is your weakest control rather than an average, so a gap here pulls the whole score down.
MFA is applied to all users accessing important data. MFA uses phish-resistant methods (FIDO2 keys, certificates, or equivalent). MFA events are logged.
MFA is phishing-resistant for all users accessing important data. MFA logs are monitored centrally. The second factor cannot be used in isolation.
Not sure which level you should aim for?
Three questions about your regulatory position and the data you keep will point you at the right target.
Take the maturity pickerThe rollout
Setting up multi-factor authentication in your environment.
You get the strongest methods first: Microsoft Authenticator with number matching for staff, and a physical security key for admin accounts. Text-message codes are switched off, because a criminal can take over the mobile number they go to. Microsoft Conditional Access then asks for a second factor whenever someone signs in from an unmanaged device or an unusual location. Every prompt is logged, and a run of failed ones is treated as a detection signal, not a support ticket.
Free self-assessment
No email required.
Score yourself on all eight controls.
Eight questions, your estimated Essential Eight maturity level, and a branded PDF report you can share with your board, insurer, broker or auditor. Runs entirely in your browser. Nothing is sent to us unless you choose to book a call.
Take the self-assessmentAsked on client calls
Questions we get about multi-factor authentication.
- We already have MFA on email. Isn't that enough?
- No. Email is where MFA started, and it is not where an attacker stops. Admin consoles, remote access gateways, cloud apps and file-sharing services all need it too. Partial MFA is worse than it looks, because it creates false confidence. The attacker just uses the account that hasn't got it.
- What about SMS codes? Those are still common.
- Text-message codes (SMS) are deprecated in the current ACSC model and in most modern security frameworks. SIM-swap attacks on Australian mobile numbers are now routine work for criminals. Moving you off SMS is part of every MFA rollout we do.
- Our staff hate MFA prompts. What can you do?
- We tune Conditional Access so trusted devices on your network don't prompt every session, only when the risk signals change. That typically brings it down to a few prompts a week per person. Number matching and FIDO2 keys are also quicker than typing a code. Staff settle within the first week.
- What happens if someone loses their MFA device?
- There is a verified recovery process. We ring the number we already hold for them and confirm their identity through their manager. Then they get a temporary access pass and enrol a new device. It works the same way whether the phone was lost on holiday or the key was left in a car park. Nobody gets an MFA bypass just this once.
Where to go next
Essential Eight controls that work with multi-factor authentication.
Control 05
Restrict administrative privileges
Making sure only the people who need admin rights have them, and only when they need them.
Read the controlControl 08
Regular backups
Keeping copies of your important data somewhere safe, and regularly testing that you can actually restore them.
Read the controlControl 04
User application hardening
Turning off features in web browsers and Office that attackers commonly abuse.
Read the controlThe maturity level summaries on this page are a plain-English version of the ACSC's published Essential Eight Maturity Model. For the full text, see the ACSC Essential Eight Maturity Model .
The qualifier
Let's see if we're a fit.
Seven questions, one moment of your time. We'd rather tell you now than three months in.