Skip to content
arrow_back
search
E8-MF-ML2.1 bolt ASD Essential Eight

Multi-factor authentication for privileged users of systems

Ensure privileged users use more than just a password to access systems.

record_voice_over

Plain language

This control ensures that users with special access rights, like IT staff, use more than just a password to access important systems. It's like adding a second lock to your front door; even if a thief copies your key (or password), they won't get in without the second key. Without it, hackers could easily take over systems and steal sensitive information.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Multi-factor authentication is used to authenticate privileged users of systems.
bolt ASD Essential Eight E8-MF-ML2.1
priority_high

Why it matters

Without MFA, attackers can hijack privileged accounts, potentially leading to full system control and catastrophic data breaches.

settings

Operational notes

Review MFA sign-in logs for privileged accounts, alert on failed prompts, and ensure all new admin accounts are enrolled in MFA immediately.

Mapping detail

Mapping

Direction

Controls