Short answer
Use MFA wherever it is available and for authentication to cloud services. Offered MFA includes paid or connected options; a licence cost is not itself an exemption. Document a service that genuinely has no compatible MFA and agree treatment with the assessor. Do not treat an administrator, contractor, emergency or service account as a blanket cloud-MFA exception; identify interactive and non-interactive paths separately.
Why this matters
An MFA licence or registration is not proof of enforcement. Check the actual authentication paths: MFA is required where available, and cloud authentication must use MFA.
Assessors need to understand user, administrator and third-party access. Verify effective policies and prevent bypasses of mandatory cloud MFA. Phishing-resistant administrator authentication is strong additional practice; a fresh prompt on every request is not a universal scheme rule.
What to check next
- Check every user account, not just staff with Microsoft 365 licences.
- Disable legacy authentication paths that cannot support MFA.
- Separate day-to-day and administrator accounts and protect both with MFA.
Official sources and related Fig Group guidance
For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.