Skip to content
arrow_back
search
E8-MF-ML2.6 bolt ASD Essential Eight

MFA success and failure events are centrally logged

Ensure all successful and failed MFA attempts are logged in one central location.

record_voice_over

Plain language

This control is about keeping track of who is trying to get into your systems by logging all successful and unsuccessful attempts to use additional security checks, like codes sent to phones, to access accounts. Without it, a hacker could try many times to break in without anyone noticing, making it easier for them to access sensitive information.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Successful and unsuccessful multi-factor authentication events are centrally logged.
bolt ASD Essential Eight E8-MF-ML2.6
priority_high

Why it matters

If MFA success and failure events aren’t centrally logged, MFA abuse and credential-stuffing activity may be missed, delaying detection and response to account compromise.

settings

Operational notes

Ensure all MFA providers forward success/failure events to a central SIEM, retain logs, and alert on repeated failures, impossible travel, or MFA fatigue prompts across multiple accounts.

Mapping detail

Mapping

Direction

Controls