Skip to content
arrow_back
search
E8-MF-ML1.1 bolt ASD Essential Eight

Require multi-factor authentication for sensitive online services

Ensure users use multiple ways to verify their identity when accessing sensitive company data online.

record_voice_over

Plain language

This control means using more than just a password to access sensitive online systems, like those that store company data. It's important because if someone steals a password, they could access valuable information. Multi-factor authentication makes it much harder for unauthorised people to get in.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.
bolt ASD Essential Eight E8-MF-ML1.1
priority_high

Why it matters

Without MFA, a compromised password can allow unauthorised access to sensitive online services, leading to exposure of sensitive data and potential financial loss.

settings

Operational notes

Enforce MFA on all online services handling sensitive data, require phishing-resistant methods where possible, and review enrolment/coverage regularly (including admins and remote access).

Mapping detail

Mapping

Direction

Controls