Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
IT-01IT SYSTEMSOFFICIAL INTENTEXPERT REVIEWED

Phishing-Resistant Multi-Factor Authentication (MFA)

Passwords alone are not enough. Phishing-resistant MFA — FIDO2 security keys, platform passkeys, or PIV — removes the shared secret an attacker can steal. Start with privileged and remote-access accounts, then expand to the full workforce.

Official intent

What the campaign asks for

Adopt multi-factor authentication that resists phishing, prioritizing privileged users and remote access. The official source remains authoritative.

Read the official campaign ↗

Why it matters

Stolen credentials remain a common path into DIB business systems. This practice turns a phished password into a dead end instead of an account takeover.

Minimum / Strong / Advanced

1
Minimum

Privileged and remote-access accounts use phishing-resistant MFA.

2
Strong

All workforce accounts are enrolled and legacy authentication protocols are blocked.

3
Advanced

Passwordless by default with continuous sign-in risk evaluation.

Implementation timeline

First 24 hours
  • List accounts with admin or remote access
  • Enable MFA for those accounts today
Next 30 days
  • Enroll the remote workforce
  • Pilot FIDO2 keys or passkeys with one team
Next 60 days
  • Extend to the full workforce
  • Block legacy protocols that bypass MFA
By day 90
  • Review enrollment coverage
  • Test fallback and recovery paths

Implementation steps

  1. Inventory identity providers and privileged accounts.
  2. Choose a phishing-resistant method your stack supports: FIDO2, passkeys, or PIV.
  3. Enforce MFA for admins and remote access first; measure coverage.
  4. Block legacy authentication that bypasses MFA.
  5. Document fallback, recovery, and break-glass procedures.

Validation

  • Attempt sign-in with password only on a test account — it must fail.
  • Review sign-in logs for legacy-protocol authentications; target zero.
  • Confirm coverage by privilege tier: enrolled accounts divided by active accounts.

Evidence to retain

Governance

MFA policy with named owner and scope

Configuration

Identity-policy export showing enforcement

Operations

Monthly enrollment-coverage report

Validation

Quarterly sign-in-log and recovery-path review

Common failure modes

What looks done but is not

SMS one-time codes for administrators, MFA enabled but not enforced, and legacy protocols left open. Enrollment without enforcement is not completion.

Framework mappings

Independent mappings are aids, not authoritative equivalence or compliance determinations.

FrameworkRequirementRelationshipConfidence
NIST SP 800-1713.5.3SupportingHigh
CMMC Level 2IA.L2-3.5.3SupportingHigh
CIS Controls v8.16.5DirectModerate