Skip to main content
Guidance

Multi-factor authentication for your corporate online services

Advice on implementing strong methods of MFA for accessing corporate online services.

Page 7 of 7

Choosing online services with the right authentication

iStock.com/Abdul Basit Noohani

In summary, the NCSC recommend that you:

  • ensure all users and administrators are required to use MFA when accessing sensitive data in an online service

  • only choose online services that support strong-enough methods of MFA, based on the sensitivity of data that will be stored and processed

  • prefer online services that support multiple methods of MFA, especially those that include phishing-resistance

  • prefer online services that support corporately-trusted SSO and context-aware authentication

Reviewed

Version

2.0