Skip to content
arrow_back
search
E8-MF-ML1.3 bolt ASD Essential Eight

Use multi-factor authentication for non-sensitive third-party services

Use a second form of verification for accounts on services handling non-sensitive org data.

record_voice_over

Plain language

Using multi-factor authentication (MFA) means that when you log in to an account, you need to provide two forms of identification instead of just a password. Imagine you're trying to get into a nightclub; you'll need both a password and an ID card, not just one or the other. This added step helps prevent hackers from getting into your accounts if they manage to steal your password. It's like having a deadbolt on your door instead of just a regular lock.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.
bolt ASD Essential Eight E8-MF-ML1.3
priority_high

Why it matters

Without MFA, stolen credentials for third-party services could allow unauthorised access to accounts and non-sensitive organisational data.

settings

Operational notes

Regularly review third-party services for MFA availability and enforce it; re-check settings after vendor changes and user onboarding to prevent drift.

Mapping detail

Mapping

Direction

Controls