Skip to content
arrow_back
search
E8-MF-ML1.4 bolt ASD Essential Eight

Use multi-factor authentication for online services handling customer data

Ensure users use multi-factor logins for online services with sensitive customer data.

record_voice_over

Plain language

This control is about using more than just a password to log into online services that handle sensitive customer information. It's important because relying only on passwords can make it easier for hackers to break into these systems, which could lead to your customers' private data being stolen or misused.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.
bolt ASD Essential Eight E8-MF-ML1.4
priority_high

Why it matters

Without MFA, stolen passwords can allow unauthorised access to online customer services, exposing sensitive customer data and causing breaches and reputational damage.

settings

Operational notes

Enforce MFA on all accounts for online customer services handling customer data; regularly review MFA logs and promptly investigate unusual authentication attempts.

Mapping detail

Mapping

Direction

Controls