Guidance
Multi-factor authentication for your corporate online services
Advice on implementing strong methods of MFA for accessing corporate online services.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 7 of 7

In summary, the NCSC recommend that you:
ensure all users and administrators are required to use MFA when accessing sensitive data in an online service
only choose online services that support strong-enough methods of MFA, based on the sensitivity of data that will be stored and processed
prefer online services that support multiple methods of MFA, especially those that include phishing-resistance
prefer online services that support corporately-trusted SSO and context-aware authentication