What is multi-factor authentication?
Where it stops an attack.
- The attack A fake Microsoft 365 sign-in page captures a staff member’s password.
- Stopped here Signing in also needs something the attacker doesn’t have. Phishing-resistant methods won’t work on a fake page at all.
- The result The stolen password is useless on its own.
Essential 8 MFA requirements by maturity level
What changes at each level.
Each level includes everything in the one before. A plain-English summary, not the requirement text. ASD Essential Eight Maturity Model (November 2023)
How to implement MFA
Protection first, disruption last.
- 01
Block legacy authentication
Old sign-in protocols skip MFA entirely, so they go first. - 02
Enforce MFA for everyone
Conditional Access in Microsoft 365, with an exceptions list that stays short. - 03
Move to phishing-resistant methods
Passkeys or FIDO2 security keys, admins first, then staff. - 04
Cover third-party services
Accounting, practice management, banking and remote access, not just Microsoft 365.
Common MFA mistakes
Where rollouts go wrong.
-
SMS codes as the end state
Better than nothing, but open to SIM swaps and phishing.
-
Push fatigue
Staff approving prompts they didn’t start. Use number matching or passkeys.
-
Permanent “temporary” exclusions
Service accounts and one-off exceptions nobody removes.