Skip to content

Multi-factor authentication

Does MFA apply to admin accounts?

Apply the same availability and mandatory cloud-authentication rules to administrator accounts, and keep administration separate from everyday work. Phishing-resistant methods such as FIDO2 security keys are strong recommendations for privileged access; Cyber Essentials does not universally prescribe a particular brand or hardware key.

Short answer

Apply the same availability and mandatory cloud-authentication rules to administrator accounts, and keep administration separate from everyday work. Phishing-resistant methods such as FIDO2 security keys are strong recommendations for privileged access; Cyber Essentials does not universally prescribe a particular brand or hardware key.

Why this matters

An MFA licence or registration is not proof of enforcement. Check the actual authentication paths: MFA is required where available, and cloud authentication must use MFA.

Assessors need to understand user, administrator and third-party access. Verify effective policies and prevent bypasses of mandatory cloud MFA. Phishing-resistant administrator authentication is strong additional practice; a fresh prompt on every request is not a universal scheme rule.

What to check next

  • Check every user account, not just staff with Microsoft 365 licences.
  • Disable legacy authentication paths that cannot support MFA.
  • Separate day-to-day and administrator accounts and protect both with MFA.

Official sources and related Fig Group guidance

For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.