Skip to content
arrow_back
search
E8-MF-ML1.7 bolt ASD Essential Eight

Multi-factor authentication combines two factors like a device and a PIN

Use something you have and something you know to secure access to important data.

record_voice_over

Plain language

Multi-factor authentication is like adding another lock on the door to your online accounts. Instead of relying just on a password, it requires an additional step, like a text message to your phone, making it much harder for bad actors to break in and access your sensitive information.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.
bolt ASD Essential Eight E8-MF-ML1.7
priority_high

Why it matters

Without MFA using a device plus PIN/biometric, stolen passwords can allow account takeover, unauthorised access and data compromise.

settings

Operational notes

Maintain MFA that combines a device with a PIN/biometric; review enrolled authenticators, revoke lost devices, and prefer phishing-resistant methods.

Mapping detail

Mapping

Direction

Controls