Skip to content
arrow_back
search
E8-MF-ML1.5 bolt ASD Essential Eight

Multi-factor authentication for third-party services with sensitive customer data

Use multi-factor authentication to secure accounts on third-party services that handle your sensitive customer data.

record_voice_over

Plain language

This control requires the use of multi-factor authentication (MFA) when accessing third-party services that manage your customer's sensitive information. This is like adding an extra lock to your digital accounts, making it much harder for unauthorised people to break in and access private data. Without this, cybercriminals can more easily steal your customers' personal information and misuse it, which could harm your business's reputation and bottom line.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.
bolt ASD Essential Eight E8-MF-ML1.5
priority_high

Why it matters

Without MFA, unauthorised access to third-party customer services could expose sensitive customer data, harming trust and triggering regulatory penalties.

settings

Operational notes

Regularly verify MFA is enforced on all third-party customer service logins (incl. admin/break-glass and SSO/SAML), and review vendor reports for drift.

Mapping detail

Mapping

Direction

Controls