Skip to content
arrow_back
search
ISM-1919 policy ASD Information Security Manual (ISM)

Disable Non-MFA Authentication Protocols

Ensures systems only use multi-factor authentication by disabling less secure protocols.

record_voice_over

Plain language

Multi-factor authentication (MFA) requires you to use two or more methods to prove who you are before you can access online services, like email or bank accounts. This control is about turning off old ways of logging in that don't use MFA, which helps to keep your accounts safer. Without it, hackers have an easier time breaking into your accounts using stolen passwords or tricking you with phishing attempts.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When multi-factor authentication is used to authenticate users or customers to online services or online customer services, all other authentication protocols that do not support multi-factor authentication are disabled.
policy ASD Information Security Manual (ISM) ISM-1919
priority_high

Why it matters

If non-MFA protocols remain enabled, attackers can bypass MFA (e.g., legacy/basic auth) to take over accounts and access data.

settings

Operational notes

Audit identity providers and apps to disable legacy/non-MFA protocols (e.g., basic/IMAP/POP/SMTP auth) and alert on any attempted use.

Mapping detail

Mapping

Direction

Controls