Skip to content
arrow_back
search
E8-MF-ML3.1 bolt ASD Essential Eight

Multi-factor authentication is used to authenticate users of data repositories

Use multiple verification methods to authorize access to data storage systems.

record_voice_over

Plain language

Multi-factor authentication (MFA) is like having two locks on your door instead of one. It protects your important data by making sure that anyone trying to access it has to prove their identity in more than one way, such as knowing a password and having a mobile phone. Without MFA, cybercriminals could more easily gain access to sensitive information, potentially leading to data breaches or financial loss.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Multi-factor authentication is used to authenticate users of data repositories.
bolt ASD Essential Eight E8-MF-ML3.1
priority_high

Why it matters

Without MFA, unauthorised access to data repositories is more likely, increasing exposure of sensitive data and resulting in breaches and reputational damage.

settings

Operational notes

Audit MFA on all data repositories so every access path (admin console, user UI and API/service accounts) enforces MFA, and remediate any exceptions promptly.

Mapping detail

Mapping

Direction

Controls