Skip to content
arrow_back
search
E8-MF-ML1.6 bolt ASD Essential Eight

Multi-factor authentication for customer access to online services handling sensitive data

Require multiple forms of ID for customer logins to protect sensitive online data.

record_voice_over

Plain language

This control ensures that when customers log in to online services handling sensitive data, they use more than just a password. This makes it much harder for someone to break in and access private information if passwords are stolen.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.
bolt ASD Essential Eight E8-MF-ML1.6
priority_high

Why it matters

Without MFA, attackers can take over customer accounts via stolen passwords, exposing sensitive customer data and damaging trust.

settings

Operational notes

Enforce MFA for all customer logins to services handling sensitive data, support strong factors, and alert on repeated failures and new-device sign-ins.

Mapping detail

Mapping

Direction

Controls