One of the eight mitigation strategies in the Essential Eight, checked against 7 tests at Maturity Level One.
MFA demands a second proof of identity beyond a password, so a stolen or guessed password alone is not enough to get in.
Why it matters
Password reuse and phishing are how most breaches start. MFA is the highest-value control you can switch on quickly, and insurers and contracts increasingly expect it.
Where Intelligence Group fits
- Require MFA for every member of staff, not only administrators
- Apply MFA to remote access, webmail and anything that faces the internet
- Choose phishing-resistant methods over SMS wherever you can
- Enforce MFA for privileged and vendor accounts with no exceptions
- Keep enrolment and enforcement reports as evidence
Where Intelligence Group fits
Intelligence Group rates this strategy from the evidence your organisation already generates, reports the maturity level it supports, and sets out the next step to lift it.
Official guidance: ASD Essential Eight Maturity Model

