Official intent
Adopt multi-factor authentication that resists phishing, prioritizing privileged users and remote access. The official source remains authoritative.
Read the official campaign ↗Why it matters
Stolen credentials remain a common path into DIB business systems. This practice turns a phished password into a dead end instead of an account takeover.
Minimum / Strong / Advanced
Privileged and remote-access accounts use phishing-resistant MFA.
All workforce accounts are enrolled and legacy authentication protocols are blocked.
Passwordless by default with continuous sign-in risk evaluation.
Implementation timeline
- List accounts with admin or remote access
- Enable MFA for those accounts today
- Enroll the remote workforce
- Pilot FIDO2 keys or passkeys with one team
- Extend to the full workforce
- Block legacy protocols that bypass MFA
- Review enrollment coverage
- Test fallback and recovery paths
Implementation steps
- Inventory identity providers and privileged accounts.
- Choose a phishing-resistant method your stack supports: FIDO2, passkeys, or PIV.
- Enforce MFA for admins and remote access first; measure coverage.
- Block legacy authentication that bypasses MFA.
- Document fallback, recovery, and break-glass procedures.
Validation
- Attempt sign-in with password only on a test account — it must fail.
- Review sign-in logs for legacy-protocol authentications; target zero.
- Confirm coverage by privilege tier: enrolled accounts divided by active accounts.
Evidence to retain
MFA policy with named owner and scope
Identity-policy export showing enforcement
Monthly enrollment-coverage report
Quarterly sign-in-log and recovery-path review
Common failure modes
SMS one-time codes for administrators, MFA enabled but not enforced, and legacy protocols left open. Enrollment without enforcement is not completion.
Framework mappings
Independent mappings are aids, not authoritative equivalence or compliance determinations.