Skip to main content
Guidance

Multi-factor authentication for your corporate online services

Advice on implementing strong methods of MFA for accessing corporate online services.

Page 2 of 7

Why MFA matters

iStock.com/Abdul Basit Noohani

Before the adoption of public cloud services, organisations hosted their corporate digital services on their private premises, accessible only via their local network. Usernames and passwords were added to these services to authenticate requests for access to corporate data. For these services, physical access to the network from only inside the work premises acted as a ‘pseudo second factor’. That is, the user authenticates by demonstrating they:

  • know a correct secret password
  • are present at the physical private network

However, organisations are increasingly storing their corporate sensitive data in online services (that is, services that are exposed to the internet). These online services are commonly hosted in the cloud, or on-premises reachable using a remote connection such as a virtual private network (VPN) or zero trust network access (ZTNA). 

The loss of this pseudo second factor (that is, the lack of only local access to the network) means that authenticating a user to an online service using only a password is not strong enough to protect any sensitive data.

We know that attackers have many ways to steal passwords, which is why the NCSC's password guidance advises that administrators implement MFA to provide additional protection. However, in response to increased adoption of MFA, attackers have developed new methods to access accounts protected by weaker methods of MFA. For example:

  • the One-Time Password (OTP) interception attack (or ‘machine-in-the-middle attack'), where a user is convinced to enter their OTP code into a disguised phishing website, giving the attacker the credentials they need to sign-in to the real website as that user
  • the push notification fatigue attack (or ‘prompt bombing attack’), where a user is bombarded with approval prompts until they mistakenly approve the attacker’s sign-in request


Reviewed

Version

2.0