Skip to content
arrow_back
search
E8-MF-ML3.2 bolt ASD Essential Eight

Phishing-resistant multi-factor authentication for online customer services

Use multi-factor authentication that resists phishing for customers accessing online services.

record_voice_over

Plain language

This control is about making sure that when customers use your online services, they have to pass a stronger security check that can't be easily tricked by scams or fake websites. Without this, criminals could pretend to be your customers and access sensitive information, causing harm to your business and your customers.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.
bolt ASD Essential Eight E8-MF-ML3.2
priority_high

Why it matters

Without phishing-resistant MFA, criminals can hijack customer accounts via phishing, enabling fraud, data exposure and reputational harm.

settings

Operational notes

Use phishing-resistant MFA (FIDO2/WebAuthn or passkeys) for customers; disable SMS/OTP where possible and verify redirects and origin binding in login flows.

Mapping detail

Mapping

Direction

Controls