Multi-factor authentication is now a condition of insurance, not a nice-to-have
Three of our clients renewed cyber policies this spring and all three carriers required enforced MFA on email and remote access. Here is the shortest path to compliance in a Microsoft 365 tenant.
Read the full note
Every cyber-liability renewal we reviewed between February and June of this year asked the same question in slightly different words: is multi-factor authentication enforced for all users on email, VPN and remote desktop access? Carriers are no longer accepting “available” as an answer. They want enforcement, and increasingly they want a screenshot of the conditional access policy.
What enforcement actually means
Having MFA switched on per-user is not enforcement. A tenant where twelve of fifteen staff have registered an authenticator app still has three accounts an attacker can use, and those three are usually the owner, the bookkeeper and a shared reception mailbox — the exact accounts that matter. Enforcement means a tenant-wide policy that blocks sign-in without a second factor, with a documented, time-limited exception list.
The order we use
- Inventory every account, including shared mailboxes, service accounts and old contractor logins. Most offices we assess have between two and nine accounts nobody can identify.
- Disable legacy authentication protocols. Enforcing MFA while POP, IMAP and SMTP basic auth remain open leaves a bypass wide open.
- Register staff during a single scheduled session, not by email announcement. Ninety minutes with the team saves three weeks of chasing.
- Move break-glass administrator accounts to hardware keys and store them physically, sealed and logged.
- Enable sign-in risk reporting and actually read it weekly for the first month.
In our experience the entire project takes one working day for an office under thirty staff, plus a two-week tail for stragglers. The insurance saving alone has covered the cost for every client who has asked us to quote it.
What breaks
Expect three categories of friction: multifunction copiers that scan-to-email using basic authentication, legacy line-of-business software with hard-coded mail credentials, and staff who use a personal device they do not want to enrol. All three have clean solutions — an SMTP relay connector, an application password scoped to a single mailbox, and a desk-based hardware token respectively. None of them justify leaving the tenant unprotected.
Questions about this piece? Call 909-292-2279 or email marketing@news.pakcomputersolution.com.