HomeControl Library › 3.5.3
3.5 Identification & Authentication5 pts

3.5.3 — Multifactor authentication (MFA)

Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

MFA for all admins everywhere, and for all users over the network.

What it actually means

One of the single highest-value controls. You need MFA for: local AND network access to privileged accounts, and network access to non-privileged accounts. Use phishing-resistant factors where you can — an authenticator app or a FIDO2 hardware key, not SMS. (See our guide on whether a Microsoft PIN counts.)

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

Partial credit: the DoD methodology deducts 5 points if MFA isn't implemented at all, but only 3 if it covers remote and privileged accounts but not general users on the local network — so partial coverage still helps your score while you finish.

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library