Skip to main content
Guidance

Multi-factor authentication for your corporate online services

Advice on implementing strong methods of MFA for accessing corporate online services.

Page 4 of 7

Mandating strong MFA for access to sensitive data

iStock.com/Abdul Basit Noohani

You should mandate strong MFA for every user accessing sensitive data. This reduces the likelihood of unauthorised users accessing it. To do this the online service will need to confirm:

  • if there is a need to authenticate a user (based on the service or the data being accessed)
  • if MFA has already been completed, and if this is the case, that the completed MFA is strong enough for the access being requested

The exact implementation will vary per-service, but a few common implementations of initial authentication and re-authentication are described below.

Initial authentication:

  • Corporately-trusted single sign-on (SSO): The user needs to complete strong MFA when they first sign in to their corporate SSO identity. When accessing an online service, they choose to use the appropriate ‘Sign in with…’ provider option. The service checks if their existing MFA sign-in is trusted and strong enough. If it is, they are signed in. This avoids unnecessarily repeated authentication. 
  • Direct sign-in from a trusted device: The user needs to complete MFA when they first sign in to a service using a device that the service has not seen them use before. After completing MFA, the user can tell the service to ‘remember this device’ if they trust it. The service can keep track of the user’s trusted devices, so it does not need to ask for MFA again until such a time as that device becomes untrustworthy.

In-session re-authentication:

  • Context-aware authentication: The user is prompted to complete MFA again if a request has been determined to be ‘risky enough' (such as coming from an abnormal place, or performing an abnormal action for that user).
  • Step-up authentication: The user needs to complete MFA any time they request a particular high-risk action, such as changing an important setting or approving a large financial transaction. 

You should favour corporately-trusted SSO and context-aware authentication when supporting MFA for online services where possible. These methods offer the best balance of security and usability. However, the most important part is that a user has completed a ‘strong enough’ form of MFA before they access sensitive data.

Reviewed

Version

2.0