Skip to main content
IDENTITY-ACCESS-MANAGEMENT5 MIN READ

Match the authenticator to the risk

Select authentication strength by mapping account risk to assurance level and phishing resistance.

The move: choose MFA by failure mode. Do not ask only whether an account has MFA. Ask what kind of attacker it can resist. A payroll admin, an identity administrator, and a low-risk wiki reader do not need the same assurance level. Use three questions. What happens if this account is compromised? Can the factor be phished or socially transferred? What happens if the user loses the authenticator? Strong authentication includes recovery planning because weak recovery can undo strong login. Phishing-resistant authenticators, including FIDO2/WebAuthn passkeys and security keys, are strongest for high-impact users because the proof is bound to the…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us