MFA. WebAuthn first. TOTP second. SMS OTP last.
Multi-factor authentication is the single most important Essential 8 mitigation. But not all MFA is equal — WebAuthn / passkeys are phishing-resistant by design; TOTP is strong but phishable via relay; SMS OTP has been deprecated by NIST since 2017. Below is the 6-method comparison + the 3 maturity levels + practical rollout guidance.
Why this lives on XIntelliSync, not on an identity-provider blog
MFA enforcement runs on your identity provider (Okta / Duo / Microsoft Entra / Google Workspace) — not on your accounting platform. XIntelliSync does not track your MFA rollout status, does not flag your admin accounts without MFA, and does not manage your privileged-access policies. What XIntelliSync DOES: enforces MFA on access to YOUR XIntelliSync account (per the platform's own auth config) and is subject to platform-side cyber posture via XGVS code-audit gates. Your customer-side MFA implementation sits with your IT team and your identity provider. The article below is the four MFA strength tiers (phishing-resistant / device-bound / app-based / SMS-fallback) and the Essential 8 strategy #6 implementation guide.
Six MFA methods — strongest to weakest
Pick the strongest your platform supports.
WebAuthn / Passkeys (FIDO2)
StrongestUse case — Public-key cryptography bound to device. Phishing-resistant by design — credential cannot be intercepted or replayed. Supported by all major browsers + iOS / Android / Windows / macOS native authenticators. Recommended for ML 2 + ML 3.
Weakness — Requires modern device + browser support. Account recovery if device lost requires backup authenticator + recovery flow.
Hardware security keys (YubiKey, Titan)
StrongestUse case — Physical USB/NFC/Bluetooth devices. Phishing-resistant via FIDO2/WebAuthn protocol. Recommended for high-privilege accounts (admin + officer + finance + IT). Best practice: 2 keys per user (primary + backup stored offsite).
Weakness — Hardware cost (~$50-$80 per key). Lost-key incidents require IT recovery process. Not all SaaS apps support hardware keys.
TOTP (Time-Based One-Time Password)
StrongUse case — Apps like Google Authenticator, Microsoft Authenticator, Authy, 1Password generate 6-digit codes refreshed every 30 seconds. Stronger than SMS — no SIM-swap risk + no SS7 interception. Recommended for ML 1 baseline.
Weakness — Phishable via real-time relay attacks (attacker presents fake login + relays code to real site). Recovery codes need secure storage. Lost-device scenarios can lock users out.
Push notification (Microsoft Authenticator, Duo, Okta Verify)
StrongUse case — App pushes approval prompt to phone. User taps Approve / Deny. Includes number-matching verification (user enters number shown on login screen) to prevent MFA-fatigue + accidental approval.
Weakness — MFA-fatigue attacks where attacker spams approvals until user clicks Approve. Mitigated by number-matching. Vendor-specific (Microsoft Authenticator + Microsoft 365 ecosystem).
Email magic link / OTP
ModerateUse case — Time-bound URL or code sent to email. Acceptable for low-risk consumer accounts. NOT acceptable for admin / privileged / financial accounts — email account compromise breaks the chain.
Weakness — If email account is compromised (often via phishing), the magic link is also compromised. Treat as a single factor only — combine with another factor.
SMS OTP
WEAK (break-glass only)Use case — Text message with 6-digit code. Phishable (real-time relay) AND SIM-swap-vulnerable AND SS7-protocol-vulnerable. NIST has deprecated SMS OTP since 2017. ACSC + ASD recommend AGAINST as primary MFA.
Weakness — SIM-swap attacks (attacker convinces telco to port the number); SS7 interception by sophisticated actors; phishing via real-time relay; SMS delivery failures during incidents. Use only as break-glass + transition customers off it.
ACSC Essential 8 Maturity Model
ML 1 baseline. ML 2 sensitive. ML 3 critical.
Baseline
Phishing-resistant MFA on all internet-facing services + customer-facing systems. TOTP minimum acceptable; WebAuthn / passkeys preferred for new deployments. SMS OTP unacceptable as primary.
Target — Routine PII handling. Most XIntelliSync SMB customers.
Sensitive information
ML 1 + MFA on all privileged users + service accounts + email accounts. Phishing-resistant MFA (WebAuthn / passkeys / hardware keys) required for admin accounts. Service accounts use credential rotation + privileged access management.
Target — Healthcare + legal + finance + tech + APRA-regulated entities. Sensitive-information regimes under APP 3.3.
Critical infrastructure
ML 2 + MFA on every authenticated action (re-auth on sensitive operations). Phishing-resistant MFA mandatory for ALL users (no TOTP fallback). Continuous adaptive authentication based on risk signals.
Target — Critical infrastructure (SOCI Act 2018). Defence + intelligence supply chain. Major payment providers.
Authoritative MFA sources
ACSC + NIST + FIDO Alliance.
ACSC — Multi-Factor Authentication
ACSC's authoritative MFA implementation guidance. Maturity model + recommended methods + deployment patterns + recovery considerations.
NIST SP 800-63B — Authentication Guidelines
US federal authentication standard. Authoritative international source on MFA strength + Authenticator Assurance Levels (AAL 1 / 2 / 3). SMS OTP deprecated since 2017 update. WebAuthn + hardware keys at AAL 3.
FIDO Alliance — fidoalliance.org
Industry consortium behind WebAuthn / FIDO2 / passkeys standards. Specifications + certified products + deployment guides. The standards body for phishing-resistant MFA.
ACSC Essential 8 Maturity Model
Per-strategy maturity model with explicit MFA expectations per ML. Use as audit checklist + cyber-insurance application reference.
All 22+ industries served
Recommended Essential 8 maturity per industry.
Construction
Recommended ML 1Threat surface (MFA-relevant) — BEC (business email compromise) on supplier-payment redirection. Project-management-software credentials. Site-mobile-device theft. Spear-phishing of accounts payable.
Healthcare
Recommended ML 2Threat surface (MFA-relevant) — Ransomware on practice-management systems (high-value patient data + Medicare numbers). Phishing on practitioner accounts. Medical-device security (IoT). Email exfiltration of clinical notes.
Hospitality
Recommended ML 1Threat surface (MFA-relevant) — POS terminal compromise + card-skimming. Booking-platform credentials. Wi-Fi network compromise. Loyalty programme database theft.
Retail
Recommended ML 2Threat surface (MFA-relevant) — E-commerce platform compromise (Magecart-style card skimming). POS system breach. Loyalty database theft. Supply-chain compromise via third-party plugins.
Professional Services / Consulting
Recommended ML 2Threat surface (MFA-relevant) — Spear-phishing of partners/principals. BEC on retainer-payment redirection. Engagement-server breach. Client-confidential information exposure. Insider threat (departing consultants).
Digital / Tech / SaaS
Recommended ML 3Threat surface (MFA-relevant) — Supply-chain compromise (npm/PyPI dependency). Production credential exposure (.env in commit). Cloud-misconfig (S3/GCS public). Customer-data breach via SQL injection. Insider threat (production access).
Finance / Mortgage Brokers
Recommended ML 3Threat surface (MFA-relevant) — BEC on settlement redirection ($100k-$1M+ events). Spear-phishing of brokers. Customer-credit-data breach. Underwriting-system compromise.
Legal
Recommended ML 2Threat surface (MFA-relevant) — Spear-phishing of partners. BEC on settlement-account redirection. Email account compromise exposing privileged matter. Trust account misappropriation via compromised credentials.
Childcare / Early Learning
Recommended ML 2Threat surface (MFA-relevant) — Centre-management-software breach (CCS records + child immunisation + parent ID). Photo/video leak via misconfigured storage. Phishing on educator accounts.
Education / RTOs
Recommended ML 2Threat surface (MFA-relevant) — Student information system (SIS) breach. Phishing on academic + admin staff. Research data exfiltration. Email exfiltration of student records.
Manufacturing
Recommended ML 2Threat surface (MFA-relevant) — Ransomware on operational technology (OT) systems. Supply-chain compromise via vendor portal. ERP system breach. IoT/PLC device compromise.
Transport / Logistics
Recommended ML 2Threat surface (MFA-relevant) — Telematics/GPS compromise. Driver-credential phishing. Customer-delivery-database leak. Ransomware on dispatch system.
Mining / Resources
Recommended ML 3Threat surface (MFA-relevant) — OT/SCADA system compromise. Supply-chain compromise via vendor portal. ASX-listed continuous-disclosure obligations. Foreign-state actor targeting (critical infrastructure).
Agriculture / Primary Production
Recommended ML 1Threat surface (MFA-relevant) — BEC on grain/livestock-buyer payment redirection. Phishing on farm-management-software credentials. IoT sensor compromise. Drone control system attack.
Fitness / Health Clubs
Recommended ML 1Threat surface (MFA-relevant) — Member-management-software breach (health screening + DD payment). Biometric-access-system compromise (gym fingerprints). Phishing on staff accounts.
Not-for-Profit
Recommended ML 1Threat surface (MFA-relevant) — Donor-database breach. Phishing on staff/volunteer accounts. CRM compromise. Beneficiary-data exposure (sensitive case files).
Events / Conferences
Recommended ML 1Threat surface (MFA-relevant) — Ticketing platform breach. Attendee-database leak. Phishing on event staff. Speaker-contract database compromise.
Creative / Photography / Production
Recommended ML 1Threat surface (MFA-relevant) — Cloud-storage credential compromise (Dropbox / Google Drive / Adobe). Spear-phishing of project leads. Image archive theft. Drone control system attack.
Marketing / Advertising Agencies
Recommended ML 1Threat surface (MFA-relevant) — Email-marketing platform compromise. Spear-phishing of account managers. Client-credential exposure (managed-service access). Campaign-database leak.
HR / Recruitment
Recommended ML 2Threat surface (MFA-relevant) — ATS (applicant tracking system) breach. Spear-phishing of consultants. Candidate-database leak (resumes + reference checks + bank details).
Insurance Brokers / Underwriters
Recommended ML 3Threat surface (MFA-relevant) — BEC on premium-payment redirection. Spear-phishing of brokers + claims handlers. Claims-database breach. Underwriting-system compromise. Re-insurance data flow risk.
Real Estate / Property Management
Recommended ML 2Threat surface (MFA-relevant) — BEC on settlement redirection ($500k-$2M+ events). Property-management-software breach. Trust-account credential compromise. Phishing on agents.
FAQs
Multi-factor authentication — answered.
Why is SMS OTP no longer recommended?
Three vulnerabilities. (1) SIM-swap: attacker convinces telco to port the victim's number to their SIM (often via social engineering of telco staff or compromised insider). (2) SS7 protocol: SS7 telecom signalling has known vulnerabilities exploited by sophisticated actors to intercept SMS in transit. (3) Real-time phishing relay: attacker presents fake login page + relays the SMS code to real site within 30 seconds. NIST deprecated SMS OTP in SP 800-63 since 2017. ACSC + ASD recommend WebAuthn / passkeys instead.
What is "phishing-resistant MFA"?
MFA that cannot be intercepted via phishing relay attacks. WebAuthn / passkeys / hardware security keys (FIDO2) are phishing-resistant because the cryptographic challenge is bound to the legitimate domain — a phishing site cannot complete the challenge. TOTP + push + SMS OTP are phishable via real-time relay. Essential 8 ML 1 already requires phishing-resistant MFA on internet-facing services in many implementations.
Should we use Microsoft Authenticator with number matching?
Yes for ML 1 deployments using Microsoft 365 ecosystem. Number-matching adds a verification step (user enters the 2-digit number shown on the login screen into the app) which prevents MFA-fatigue + accidental approval. Microsoft enforced number-matching globally from May 2023. Still phishable via sophisticated relay; for ML 2+ deployments use WebAuthn / passkeys / hardware keys.
How do we handle MFA for service accounts + automated processes?
Three patterns. (1) Service-principal accounts with certificate-based authentication + Privileged Access Management (PAM) tooling (CyberArk, BeyondTrust, HashiCorp Vault). (2) Workload identity federation (Azure managed identity, AWS IAM roles, GCP service accounts). (3) Short-lived credentials (1-24 hour) rotated automatically. NEVER use long-lived service-account passwords stored in code or config files.
What about MFA for executives + officers?
Highest-risk targets — executive accounts attract spear-phishing + BEC + nation-state attention. Recommendations: (1) Hardware security keys (YubiKey 5 NFC + backup) for primary authentication. (2) Mobile-device MDM (Microsoft Intune, Jamf) to enforce device security. (3) Restricted admin model — separate admin account from daily-use account. (4) Conditional access policies blocking authentication from atypical locations / devices. (5) Privileged identity management (PIM) for time-bound elevation.
How do we onboard MFA without breaking customer / staff workflow?
Four-phase rollout. (1) Inventory: which apps + accounts currently support MFA, current adoption %. (2) Pilot: enable MFA on internal IT team accounts first; iterate on enrollment + recovery flows. (3) Privileged users next: admins + executives + finance + HR — these accounts have highest risk. (4) All users: rolling enforcement with grace period + clear support channel. Communicate via multiple channels (email + intranet + manager cascade) — surprise enforcement creates lockout incidents.
How does XIntelliSync help with MFA compliance?
XIntelliSync does NOT surface your MFA enforcement status across your other services, does NOT flag your admin / privileged accounts without MFA, does NOT generate the Essential-8-self-assessment template, and does NOT track your rollout-progress dashboard. Customer-side MFA enforcement runs on your identity provider (Okta / Duo / Microsoft Entra / Google Workspace), not on your accounting platform. What XIntelliSync DOES: enforces MFA on access to your XIntelliSync account (per the platform's own auth config) and is subject to platform-side cyber posture via XGVS code-audit gates. Your customer-side MFA implementation stays with your IT team.
Continue reading