About this program
Tell us how multi-factor authentication is rolled out across your workforce, admins and third parties — get a coverage score in under 3 minutes.
Risks addressed
- Critical Stolen or phished credentials lead to account takeover
- Critical Admin accounts compromised due to weak / no MFA
- High Remote workers signed in from compromised devices without strong auth
- High Third-party / contractor sessions hijacked
Controls (7)
-
MFA enforced for all employees
HighMulti-factor authentication (MFA) requires all employees to present at least two distinct authentication factors—such as a password plus a time-based one-time password (TOTP), push notification, or hardware token—before accessing corporate systems and applications. This control is typically enforced through identity…
How to test + evidence
Testing procedure: Pull the IdP report showing MFA enrolment by user. Expect 100% of active employees enrolled.
Evidence to collect: IdP MFA enrolment CSV; conditional-access policy export.
-
MFA enforced for all administrators
CriticalMulti-factor authentication (MFA) must be enforced for all accounts with administrative privileges across systems, applications, and cloud platforms. This control requires at least two independent authentication factors (knowledge, possession, or inherence) for any user performing privileged operations such as configuration…
How to test + evidence
Testing procedure: List all privileged role assignments and verify each account has MFA + strong factor (no SMS).
Evidence to collect: Privileged role report + MFA factor list.
-
MFA enforced for remote / VPN access
HighThis control mandates that all users connecting to organizational networks via remote access methods (VPN, remote desktop gateways, or cloud-based remote access solutions) must authenticate using multi-factor authentication (MFA). MFA requires presentation of at least two distinct authentication factors—typically something…
How to test + evidence
Testing procedure: Review VPN auth config and conditional-access rule for off-network sign-ins.
Evidence to collect: VPN auth config screenshot; CA policy export.
-
MFA enforced on critical SaaS
HighThis control requires that multi-factor authentication (MFA) is mandated for all user accounts accessing business-critical Software-as-a-Service (SaaS) applications such as productivity suites, CRM platforms, HR systems, and financial management tools. MFA enforcement prevents unauthorized access even when credentials are compromised…
How to test + evidence
Testing procedure: For each Tier-1 SaaS (email, finance, HR), confirm SSO + MFA enforcement at the app level.
Evidence to collect: SaaS admin console screenshots showing SSO+MFA.
-
Phishing-resistant MFA for admins
HighPhishing-resistant multi-factor authentication (MFA) for administrative accounts requires authentication methods that cannot be compromised through social engineering, credential phishing, or session hijacking attacks. This includes hardware security keys (FIDO2/WebAuthn), platform authenticators (TPM-backed), or certificate-based authentication, explicitly excluding SMS, voice calls,…
How to test + evidence
Testing procedure: Verify privileged accounts use FIDO2 / hardware key / certificate — not SMS or push-only.
Evidence to collect: Auth-method inventory for privileged group.
-
MFA bypass / exception register reviewed quarterly
MediumThis control establishes a formal quarterly review process for all documented exceptions and bypasses to multi-factor authentication (MFA) requirements. Organizations maintain a centralized register of accounts, systems, or user groups granted temporary or permanent MFA exemptions, including business justification, approval…
How to test + evidence
Testing procedure: Pull list of users with MFA disabled or with exceptions; confirm review meeting minutes.
Evidence to collect: Exception register + review minutes.
-
MFA enforced on third-party / contractor access
MediumThis control mandates that all third-party vendors, contractors, and external personnel authenticate using multi-factor authentication (MFA) when accessing organizational systems, applications, or data. MFA requires at least two independent authentication factors (something you know, something you have, or something you…
How to test + evidence
Testing procedure: Verify external collaborators / B2B guests are subject to MFA via guest policy.
Evidence to collect: Guest CA policy + external identities report.