Skip to content
Menu

Essential Eight multi-factor authentication

A stolen password alone doesn’t get in.

Multi-factor authentication (MFA) asks for a second proof, such as a phone, passkey or security key, on top of a password.

A laptop sign-in screen, a phone showing an approval prompt and a hardware security key on a desk.

At a glance

Control
07 of 08 · Limit the impact
Stops
Stolen and guessed passwords
Typical tools
Microsoft Entra ID, Authenticator, passkeys, FIDO2 keys
Effort
Low to medium

What is multi-factor authentication?

Where it stops an attack.

  1. The attack A fake Microsoft 365 sign-in page captures a staff member’s password.
  2. Stopped here Signing in also needs something the attacker doesn’t have. Phishing-resistant methods won’t work on a fake page at all.
  3. The result The stolen password is useless on its own.
ML1 Maturity Level 1. ML2 Maturity Level 2. ML3 Maturity Level 3.
Online services with sensitive data Required on your own and third-party servicesMust be phishing-resistant No change
Customers of your online services MFA where sensitive customer data is heldAdds a phishing-resistant optionMust be phishing-resistant
Staff signing in to systems Not required Phishing-resistant MFA, admins and standard users No change
Data repositories Not required Not required Phishing-resistant MFA
Methods Something you have plus something you know, or a device unlocked by PIN or biometric No change No change
Logging Not required Successful and failed MFA events logged centrally. Internet-facing server logs analysedAdds analysis of workstation and internal server logs

Each level includes everything in the one before. A plain-English summary, not the requirement text. ASD Essential Eight Maturity Model (November 2023)

How to implement MFA

Protection first, disruption last.

  1. 01

    Block legacy authentication

    Old sign-in protocols skip MFA entirely, so they go first.
  2. 02

    Enforce MFA for everyone

    Conditional Access in Microsoft 365, with an exceptions list that stays short.
  3. 03

    Move to phishing-resistant methods

    Passkeys or FIDO2 security keys, admins first, then staff.
  4. 04

    Cover third-party services

    Accounting, practice management, banking and remote access, not just Microsoft 365.

Common MFA mistakes

Where rollouts go wrong.

  • SMS codes as the end state

    Better than nothing, but open to SIM swaps and phishing.

  • Push fatigue

    Staff approving prompts they didn’t start. Use number matching or passkeys.

  • Permanent “temporary” exclusions

    Service accounts and one-off exceptions nobody removes.

MFA and phishing-resistant MFA questions

What clients ask before we start.

What is phishing-resistant MFA?
Is Microsoft Authenticator phishing-resistant?
What are the Essential 8 MFA requirements at Maturity Level 2?

Find out where you stand on multi-factor authentication.

Book a free 45-minute Essential Eight review with a Perth engineer. You get your maturity on all eight controls and what to fix first. The report is yours to keep.

Or call (08) 9467 2269

What’s bugging you
Staff

A Perth engineer, not a salesperson, replies within one business day.

We hold ISO/IEC 27001:2022 certification from BSI, certificate IS 840964.