Skip to content
arrow_back
search
E8-MF-ML2.2 bolt ASD Essential Eight

Use multi-factor authentication for unprivileged user access

Require additional authentication methods for regular system users.

record_voice_over

Plain language

This control is about requiring more than just a password to access your systems. It's like adding an extra lock to your door. It makes it much harder for someone to break in and steal valuable information, even if they guess your password.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Multi-factor authentication is used to authenticate unprivileged users of systems.
bolt ASD Essential Eight E8-MF-ML2.2
priority_high

Why it matters

Without MFA for unprivileged users, stolen passwords enable unauthorised access, increasing the risk of data theft and serving as a foothold for lateral movement.

settings

Operational notes

Regularly review user enrolment and exclusions to maintain full MFA coverage for unprivileged users, and assess MFA method strength (e.g. phishing-resistant) as threats evolve.

Mapping detail

Mapping

Direction

Controls