MFA for all admins everywhere, and for all users over the network.
What it actually means
One of the single highest-value controls. You need MFA for: local AND network access to privileged accounts, and network access to non-privileged accounts. Use phishing-resistant factors where you can — an authenticator app or a FIDO2 hardware key, not SMS. (See our guide on whether a Microsoft PIN counts.)
Pass or fail — an assessor needs a "yes" to each
- MFA enforced for privileged accounts on both local and network access.
- MFA enforced for all users' network access.
- Factors are reasonably strong (authenticator app / FIDO2 preferred over SMS).
What to have ready
- Identity-provider MFA / conditional-access policies
- Enrollment reports showing coverage
- Authenticator/FIDO2 configuration
Where teams trip up
- MFA only for remote/privileged users but not general users on the network
- Single-factor PIN treated as 'MFA'
- SMS as the only second factor
Partial credit: the NIST SP 800-171 DoD Assessment Methodology deducts 5 points if MFA isn't implemented at all, but only 3 if it covers remote and privileged accounts but not general users on the local network — so partial coverage still helps your score while you finish.
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Identification & Authentication (3.5)
3.5.1 — Uniquely identify users, processes, and devices3.5.2 — Authenticate before access3.5.4 — Replay-resistant authentication3.5.5 — Don't recycle identifiers3.5.6 — Disable dormant accounts3.5.7 — Enforce password complexity3.5.8 — Block password reuse3.5.9 — Force change of temporary passwords3.5.10 — Protect stored and transmitted passwords3.5.11 — Obscure authentication feedback