Weak password security is the most common means for bad actors to get their hands on sensitive information and cause a breach. Multi-factor authentication (MFA) is a better way to secure your company from a breach, so phishing-resistant MFA has become a priority as a result.
The need for multi-factor authentication (MFA) is understood, but that doesn’t mean adoption is always a smooth ride. While spending on MFA is trending up, making it work can be a rough road full of potential implementation challenges.
Multi-factor authentication (MFA) is a security technology that uses multiple ways to confirm a user’s identity when they attempt to sign in to an application. Multiple factors make it more difficult for an unauthorized user to gain access. One example of MFA is a password paired with a text or email confirmation.
MFA is a more robust authentication method than simple password authentication because it asks you to provide something you know (e.g., a username or password), something you own (e.g., a one-time code sent to your phone), and/or something you are (e.g., biometric information).
The objective of MFA is to create a defensive layer to prevent unauthorized access to a device, application, network, or data. If one factor is compromised, there are additional barriers that the threat still has to overcome before reaching the target.
At a high level, implementing MFA requires integrating your authentication system with one or more additional verification methods. First, an organization needs to select the factors it will use—such as biometrics, hardware tokens, push notifications, or security keys—based on usability and security needs. Next, these factors must be configured within the identity provider (IdP) or orchestration platform to enforce MFA policies across applications. IT teams then map which apps and users require MFA, set rules for adaptive use cases, and test rollout scenarios. Finally, organizations need to plan training and communication so employees understand how to use MFA effectively. With the right preparation, MFA can be deployed broadly without introducing unnecessary complexity or friction.
Though successfully implementing MFA can be challenging, it doesn’t have to be. You can introduce MFA throughout your organization if you know the dangers to avoid. Let’s look at the most common challenges of implementing MFA and how to avoid them.
Cyber insurance is a big deal. In order to get cyber insurance today, an organization must have all its apps secured with MFA. With the United States government’s Office of Management and Budget’s (OMB) Federal Zero Trust Strategy, Ignoring ZTA means getting cybersecurity insurance will be tricky or incredibly expensive — a huge frustration and a potential liability.
If you have to first modernize your apps one-by-one before moving them to the cloud, it takes about almost 2000 hours on average to rewrite each one. Not to mention the opportunity cost of having your valuable developers spend their time retrofitting old technology rather than on innovation.
Some companies that implement MFA also make it optional for their employees because they discover the rate of adoption is very low. Even though MFA is just as easy to use as password-only sign-on, people resist making the switch. The reason isn’t surprising. Humans are creatures of habit, especially when it comes to the path of least resistance.
Bottom line: To guarantee widespread MFA adoption at your company, make MFA implementation mandatory. You may see some initial resistance, but people adapt, and the long-term payoff is worth it.
Implementing MFA is a time- and cost-intensive venture, so it can be tempting to reduce the scope of your implementation. Some organizations apply MFA only to users with access to the most sensitive information or critical applications. A reduced scope won’t give you the protection you need.
Bad actors don’t need direct access to the most sensitive applications to succeed. Any weak point in your system can be exploited to lead to other areas within your system. If an attacker gains access to a low-risk application, it can be an entry point to access sensitive data.
Bottom line: implement MFA across all of your applications and users.
It’s possible to treat MFA as an extra step that you tack onto your security policies and procedures. While that simplifies implementation, it also makes daily usability more frustrating. This approach adds friction by complicating sign-on every time a user needs to access the system.
MFA should be handled in a way that improves the authentication process and makes it seamless for your employees. One way to do this is by incorporating adaptive MFA. Adaptive MFA uses contextual information and business rules to determine which authentication methods to use in a particular situation.
Bottom line: use adaptive MFA to grant legitimate users the appropriate level of access with fewer steps and less friction and reduce the risk of unauthorized access.
Multi-factor authentication prompts users to authenticate using two or more methods. A standard authentication method is via SMS or text messaging. It’s also an insecure method that can put you at risk of a data breach.
Cyber attackers love to go phishing with SIM-swapping techniques to steal SMS authentication codes. Additionally, SMS messages sent to your desktop are easy prey for an attacker to intercept.
Bottom line: SMS authentication is so insecure that the National Institutes of Standards and Technologies (NIST) recommends not using it at all. Use alternative authentication methods, such as biometrics, security keys, or magic links.
SMS isn’t the only insecure authentication method. Passwords are notoriously hated by security professionals. Chances are, your organization sees each of these scenarios every day:
Passwords are one of your weakest links in security. But you can eliminate that liability by opting for passwordless authentication. Users can prove who they are without the use of a password — usually by using one of three methods:
Bottom line: not only is passwordless authentication more secure, but it’s also more convenient.
People are naturally resistant to change. And for many, learning a new technology isn’t easy. Before you embark on any significant initiative, get a clear understanding of the people hurdles. Some typical pitfalls include:
Bottom line: more resistance means a longer implementation time, which increases productivity loss throughout the organization. Be sure you have this element buttoned up before you begin your MFA implementation, or you could have unwanted business impacts.
While deploying multi-factor authentication for every user and on every application is the eventual goal, it isn’t wise to do it all at once. Plan out a staged approach to your MFA adoption, and take it in small chunks so that you can learn and correct as you go.
Start with a test group — a small subset of employees who are the only users of a test-case application. This might be your accounting department using a piece of financial software that no one else uses. Implement MFA on the application and train the users on the new process.
Take notes and learn from the experience, then gradually roll out all your applications across the company. There are various rollout approaches you can use:
Bottom line: You have several valid options for implementing MFA throughout your organization, but the key is to be strategic in your rollout decision-making.
Legacy applications pose a particular challenge for multi-factor authentication: they weren’t built for modern authentication methods. Typically, the only way to implement MFA on a legacy app is to go in and rewrite the code itself. That approach is prohibitively expensive and time-consuming; many times, it isn’t even possible.
Bottom line: As a result, many organizations shrug their shoulders and elect to implement MFA everywhere throughout the company except on legacy systems. But that brings us back to pitfall number two: if you don’t implement MFA on every application, you leave a point of entry for attackers.
Fortunately, there’s a solution — and it’s easier than you might expect. You can implement MFA on legacy applications by pairing them with an identity orchestration platform.
An identity orchestration platform is like a proxy that sits between your legacy app and the user. The orchestration platform presents the user with an MFA technology. It does all the authenticating on behalf of the application, then tells the application that the user has passed the sign-on requirements.
Orchestration does all this without touching the legacy application. You don’t need to change any code, and you can implement it on any identity provider. Because no coding is involved, you can implement this solution quickly — in just hours — and inexpensively.
MFA implementation can be done successfully throughout your entire organization — even down to your legacy applications. But the difference between an effective rollout and a painful one is in your planning. Know the challenges and how to avoid them — and don’t leave your legacy applications out of the effort.