ALL NEWS
October 23, 2024
Cybersecurity

MFA Is Essential but Your Accounts Need More Protection

By InnerDigital

MFA Is Essential but Your Accounts Need More Protection

Multifactor authentication adds an important barrier to account misuse, but enabling it does not finish the security work. An employee can still be tricked into approving a request, and attackers can target the session or application access that exists after a successful sign-in.

Start by checking coverage. Identify accounts that do not require MFA, including administrators and external services. Review exceptions with a business owner and IT. An exception should have a specific reason, compensating protection where possible, and a date for reconsideration.

Evaluate the authentication methods your systems support. Phishing-resistant options can provide stronger protection against certain credential-phishing attacks than methods that rely on manually entered codes or approval prompts. Compatibility and recovery procedures matter, so pilot changes with a small group before broad deployment.

Teach employees to report unexpected prompts. Someone who repeatedly receives an approval request should deny it and contact IT through a known channel. Make sure staff understand that support should not ask them to share authentication codes or approve a login they did not initiate.

Review access after sign-in. Where your platform and licensing support it, consider controls based on device trust, location, and other risk signals. These policies require planning and testing; a poorly designed rule can lock out legitimate users or create exceptions that weaken the intended protection.

Do not overlook applications connected to business accounts. Review unnecessary permissions, forwarding rules, and delegated access. When compromise is suspected, the response may need to address active sessions and application access as well as the password. The correct steps depend on the affected service.

Give account recovery the same attention as account protection. Decide who can authorize a reset and how that person's identity will be verified. A rushed help-desk exception should not become the easiest route around otherwise strong controls.

This Cybersecurity Awareness Month, ask for a review of one important account system from enrollment through recovery. Contact InnerDigital to evaluate MFA coverage and the surrounding controls that help protect your business identities.

Reference: CISA phishing resistant MFA fact sheet