CYBER SECURITY GUIDE • PART 1
Multi-Factor Authentication
Establish comprehensive verification barriers to secure credentials. This MSP-approved checklist outlines absolute protocols for safeguarding critical systems, administrator levels, and remote work pathways.
Security Verification Controls
- Multi-factor authentication is enabled for all user accounts.
- MFA is required for administrator accounts.
- MFA is required when users access Microsoft 365 remotely.
- Employees understand how to approve legitimate sign-in requests.
- Employees know how to report an unexpected MFA notification.
- Authenticator applications are used where appropriate.
- Legacy authentication methods are disabled where they are not required.
- Emergency access arrangements are documented and protected.
- MFA registration information is reviewed when employees change devices.
- Temporary access methods are controlled and time limited.
MSP Recommendation
Prioritise MFA for every user, with stronger controls for administrators and accounts accessing sensitive information.
MFA Prevention Rate
0
%
Implementing MFA blocks nearly all automated credential hacking attempts, making it the most critical foundational control.