Skip to main content

Free audit program · v1.0

MFA Coverage Quick Check

Tell us how multi-factor authentication is rolled out across your workforce, admins and third parties — get a coverage score in under 3 minutes.

  • General target area
  • ISO 27001 framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Tell us how multi-factor authentication is rolled out across your workforce, admins and third parties — get a coverage score in under 3 minutes.

Risks addressed

  • Critical Stolen or phished credentials lead to account takeover
  • Critical Admin accounts compromised due to weak / no MFA
  • High Remote workers signed in from compromised devices without strong auth
  • High Third-party / contractor sessions hijacked

Controls (7)

  1. MFA enforced for all employees

    High

    Multi-factor authentication (MFA) requires all employees to present at least two distinct authentication factors—such as a password plus a time-based one-time password (TOTP), push notification, or hardware token—before accessing corporate systems and applications. This control is typically enforced through identity…

    How to test + evidence

    Testing procedure: Pull the IdP report showing MFA enrolment by user. Expect 100% of active employees enrolled.

    Evidence to collect: IdP MFA enrolment CSV; conditional-access policy export.

  2. MFA enforced for all administrators

    Critical

    Multi-factor authentication (MFA) must be enforced for all accounts with administrative privileges across systems, applications, and cloud platforms. This control requires at least two independent authentication factors (knowledge, possession, or inherence) for any user performing privileged operations such as configuration…

    How to test + evidence

    Testing procedure: List all privileged role assignments and verify each account has MFA + strong factor (no SMS).

    Evidence to collect: Privileged role report + MFA factor list.

  3. MFA enforced for remote / VPN access

    High

    This control mandates that all users connecting to organizational networks via remote access methods (VPN, remote desktop gateways, or cloud-based remote access solutions) must authenticate using multi-factor authentication (MFA). MFA requires presentation of at least two distinct authentication factors—typically something…

    How to test + evidence

    Testing procedure: Review VPN auth config and conditional-access rule for off-network sign-ins.

    Evidence to collect: VPN auth config screenshot; CA policy export.

  4. MFA enforced on critical SaaS

    High

    This control requires that multi-factor authentication (MFA) is mandated for all user accounts accessing business-critical Software-as-a-Service (SaaS) applications such as productivity suites, CRM platforms, HR systems, and financial management tools. MFA enforcement prevents unauthorized access even when credentials are compromised…

    How to test + evidence

    Testing procedure: For each Tier-1 SaaS (email, finance, HR), confirm SSO + MFA enforcement at the app level.

    Evidence to collect: SaaS admin console screenshots showing SSO+MFA.

  5. Phishing-resistant MFA for admins

    High

    Phishing-resistant multi-factor authentication (MFA) for administrative accounts requires authentication methods that cannot be compromised through social engineering, credential phishing, or session hijacking attacks. This includes hardware security keys (FIDO2/WebAuthn), platform authenticators (TPM-backed), or certificate-based authentication, explicitly excluding SMS, voice calls,…

    How to test + evidence

    Testing procedure: Verify privileged accounts use FIDO2 / hardware key / certificate — not SMS or push-only.

    Evidence to collect: Auth-method inventory for privileged group.

  6. MFA bypass / exception register reviewed quarterly

    Medium

    This control establishes a formal quarterly review process for all documented exceptions and bypasses to multi-factor authentication (MFA) requirements. Organizations maintain a centralized register of accounts, systems, or user groups granted temporary or permanent MFA exemptions, including business justification, approval…

    How to test + evidence

    Testing procedure: Pull list of users with MFA disabled or with exceptions; confirm review meeting minutes.

    Evidence to collect: Exception register + review minutes.

  7. MFA enforced on third-party / contractor access

    Medium

    This control mandates that all third-party vendors, contractors, and external personnel authenticate using multi-factor authentication (MFA) when accessing organizational systems, applications, or data. MFA requires at least two independent authentication factors (something you know, something you have, or something you…

    How to test + evidence

    Testing procedure: Verify external collaborators / B2B guests are subject to MFA via guest policy.

    Evidence to collect: Guest CA policy + external identities report.