Skip to content
arrow_back
E8-MF-ML2.1boltASD Essential Eight

Multi-factor authentication for privileged users of systems

Ensure privileged users use more than just a password to access systems.

record_voice_over

Plain language

This control ensures that users with special access rights, like IT staff, use more than just a password to access important systems. It's like adding a second lock to your front door; even if a thief copies your key (or password), they won't get in without the second key. Without it, hackers could easily take over systems and steal sensitive information.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

18 June 2026

E8 maturity levels

ML2

Official control statement

Multi-factor authentication is used to authenticate privileged users of systems.
boltASD Essential EightE8-MF-ML2.1
priority_high

Why it matters

Without MFA, attackers can hijack privileged accounts, potentially leading to full system control and catastrophic data breaches.

settings

Operational notes

Review MFA sign-in logs for privileged accounts, alert on failed prompts, and ensure all new admin accounts are enrolled in MFA immediately.

build

Implementation tips

  • IT team should enable multi-factor authentication for all privileged accounts by configuring it in the system settings and training users on its use.
  • System administrator should regularly review privileged accounts to ensure multi-factor authentication is consistently applied by checking system logs for compliance.
  • Security officer should choose strong authentication methods like security tokens or mobile authenticator apps, implementing them through a vendor-provided solution.
  • IT support should be available to assist users in setting up multi-factor authentication on their devices, providing clear step-by-step instructions and support contacts.
  • Management should communicate the importance of multi-factor authentication to all privileged users, explaining its role in protecting organisational data and encouraging compliance.
fact_check

Audit / evidence tips

  • AskHow is multi-factor authentication implemented for privileged users?
  • GoodDocumentation shows multifactor setup for privileged users and technical settings confirm compliance
  • AskAre there logs that show multi-factor authentication usage for privileged users?
  • GoodLogs clearly indicate that multi-factor authentication is used extensively by all privileged users
link

Cross-framework mappings

How E8-MF-ML2.1 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.5E8-MF-ML2.1 requires MFA for privileged users accessing systems
sync_altPartially overlaps(1)expand_less
Annex A 5.17Annex A 5.17 addresses establishing a management process for allocating and protecting authentication information and advising personnel ...
handshakeSupports(1)expand_less
Annex A 8.2E8-MF-ML2.1 requires MFA to authenticate privileged users of systems

ASD ISM

ControlNotesDetails
handshakeSupports(5)expand_less
ISM-0553ISM-0553 requires authentication and authorisation for all actions on a video conferencing network, including call setup and changing set...
ISM-1620ISM-1620 requires privileged accounts to use the AD Protected Users group, which helps prevent use of weaker authentication methods and r...
ISM-1816ISM-1816 requires preventing unauthorised modification of the authoritative software source
ISM-1919ISM-1919 requires disabling authentication protocols that do not support MFA whenever MFA is used, reducing the risk privileged users can...
ISM-1927ISM-1927 requires that access to key Microsoft identity servers is limited to privileged users who require access
linkRelated(1)expand_less
ISM-1173E8-MF-ML2.1 requires multi-factor authentication (MFA) to be used to authenticate privileged users of systems

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Multi-factor authentication controls, or browse the full Essential Eight mitigation strategies library.

Mapping detail

Mapping

Direction

Controls