Skip to content
arrow_back
search
E8-MF-ML2.5 bolt ASD Essential Eight

Multi-factor authentication used for system access is phishing-resistant

Ensure system login methods resist phishing attacks using multiple authentication factors.

record_voice_over

Plain language

This control ensures that logging into important systems is more secure by using two or more forms of identification, such as a password and a unique code from an app. This extra step prevents criminals from accessing sensitive information, even if they manage to steal someone’s password.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Multi-factor authentication used for authenticating users of systems is phishing-resistant.
bolt ASD Essential Eight E8-MF-ML2.5
priority_high

Why it matters

Without phishing-resistant MFA, attackers can hijack sessions via phishing and bypass OTP/push prompts, gaining unauthorised system access and data exposure.

settings

Operational notes

Use phishing-resistant MFA (FIDO2/WebAuthn passkeys or certificate-based). Disable SMS/OTP where possible and monitor for MFA fatigue and suspicious prompts.

Mapping detail

Mapping

Direction

Controls