Skip to content
arrow_back
search
E8-MF-ML2.3 bolt ASD Essential Eight

Multi-factor authentication online services must be phishing-resistant

Ensure two-factor authentication can't be bypassed by phishing attacks.

record_voice_over

Plain language

This control is about ensuring that when people log into online services, they have to use a multi-step process to verify their identity that can't be easily tricked by phishing scams. Without this, cybercriminals might fool someone into giving away their login details, and then use that information to access sensitive business data.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Multi-factor authentication used for authenticating users of online services is phishing-resistant.
bolt ASD Essential Eight E8-MF-ML2.3
priority_high

Why it matters

Without phishing-resistant MFA, attackers can exploit credential phishing, leading to unauthorised access and data breaches.

settings

Operational notes

Deploy and test phishing-resistant MFA (FIDO2/WebAuthn or passkeys); block SMS/OTP for online services to reduce credential-phishing replay.

Mapping detail

Mapping

Direction

Controls