Match the authenticator to the risk
Select authentication strength by mapping account risk to assurance level and phishing resistance.
The move: choose MFA by failure mode. Do not ask only whether an account has MFA. Ask what kind of attacker it can resist. A payroll admin, an identity administrator, and a low-risk wiki reader do not need the same assurance level. Use three questions. What happens if this account is compromised? Can the factor be phished or socially transferred? What happens if the user loses the authenticator? Strong authentication includes recovery planning because weak recovery can undo strong login. Phishing-resistant authenticators, including FIDO2/WebAuthn passkeys and security keys, are strongest for high-impact users because the proof is bound to the…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in