Skip to content
arrow_back
search
E8-MF-ML1.2 bolt ASD Essential Eight

Multi-factor authentication for third-party services handling sensitive data

Use multi-factor authentication for third-party services with sensitive data to prevent unauthorized access.

record_voice_over

Plain language

Multi-factor authentication (MFA) is like having two locks on your door instead of one. It's important because it makes it much harder for someone to break into your online services and see sensitive information, like your financial records. Without MFA, a hacker could easily steal your password and get full access.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.
bolt ASD Essential Eight E8-MF-ML1.2
priority_high

Why it matters

Without MFA on third-party services, stolen credentials can allow unauthorised access and exfiltration of sensitive organisational data.

settings

Operational notes

Confirm MFA is enforced for all third-party services handling sensitive data, and review new integrations/vendors to prevent MFA bypass.

Mapping detail

Mapping

Direction

Controls