Skip to content

Multi-factor authentication

Which MFA methods are acceptable?

Use an implementation that provides the required independent authentication factors. FIDO2 passkeys with user verification can satisfy MFA. Authenticator codes, appropriately secured push flows and SMS-based combinations can also be relevant; SMS is not universally banned by the scheme. Prefer phishing-resistant methods for higher-risk access and verify the actual configuration.

Short answer

Use an implementation that provides the required independent authentication factors. FIDO2 passkeys with user verification can satisfy MFA. Authenticator codes, appropriately secured push flows and SMS-based combinations can also be relevant; SMS is not universally banned by the scheme. Prefer phishing-resistant methods for higher-risk access and verify the actual configuration.

Why this matters

An MFA licence or registration is not proof of enforcement. Check the actual authentication paths: MFA is required where available, and cloud authentication must use MFA.

Assessors need to understand user, administrator and third-party access. Verify effective policies and prevent bypasses of mandatory cloud MFA. Phishing-resistant administrator authentication is strong additional practice; a fresh prompt on every request is not a universal scheme rule.

What to check next

  • Check every user account, not just staff with Microsoft 365 licences.
  • Disable legacy authentication paths that cannot support MFA.
  • Separate day-to-day and administrator accounts and protect both with MFA.

Official sources and related Fig Group guidance

For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.