A compromised Microsoft 365 account can give a criminal access to years of emails, invoices, contacts and password-reset messages. That is why the answer to does Cyber Essentials require MFA is usually yes – but the detail matters. Cyber Essentials requires multi-factor authentication for cloud services where it is available, rather than demanding it for every single system in precisely the same way.
For busy organisations in Bradford, Leeds and Halifax, this is good news as well as a compliance task. MFA is one of the most effective ways to stop an attacker getting in with a stolen password. The aim is not to make every member of staff wrestle with technology. It is to put a sensible extra check around the services that hold your organisation’s information.
Does Cyber Essentials require MFA for cloud services?
Yes. Under the Cyber Essentials requirements, users must use multi-factor authentication to access cloud services when the service offers it. In practical terms, this will commonly include Microsoft 365, Google Workspace, cloud storage, accounting platforms, customer relationship management systems and other software accessed online using a user account.
Email deserves special attention. It is often the key to the rest of your systems because it receives password reset requests, supplier correspondence and financial information. If your organisation uses Microsoft 365 or Google Workspace, MFA should be enabled for every relevant user account, including directors, volunteers, temporary staff and administrators.
The phrase “when available” is worth understanding. A small, specialist cloud application may not offer MFA. You would not be expected to invent a feature the supplier does not provide. However, most mainstream cloud services do offer it, and simply leaving it switched off because it feels inconvenient is unlikely to meet the requirement.
Your assessor will consider the services within your Cyber Essentials scope and the answers you provide in the assessment questionnaire. Keeping a clear record of your cloud services and how users sign in makes this far less stressful.
What counts as MFA?
MFA means proving your identity using at least two different types of factor. Usually, that is something you know, such as a password, plus something you have, such as an authenticator app, security key or approval prompt on your mobile phone.
For most small businesses and charities, an authenticator app is the practical starting point. A member of staff signs in with their password, then enters a time-limited code or approves a notification in the app. Hardware security keys can offer even stronger protection and are particularly useful for people with access to finance, senior management accounts or IT administration.
A text message code may technically be accepted as an additional factor in some setups, but it is not the strongest option. SIM-swap fraud and interception risks mean authenticator apps or security keys are generally a better long-term choice.
Two passwords do not count as MFA, even if they are for different systems. Nor do security questions, a memorable word, or typing the same password twice. The factors need to be genuinely different.
The accounts that are most often missed
Organisations usually remember to enable MFA for their everyday Microsoft 365 accounts. The problems tend to sit around the edges: an old shared mailbox login, a former staff member’s account, a website administrator, a cloud backup portal or a finance system used by only one person.
Administrator accounts need particular care. These accounts can create users, change security settings and access large amounts of data. They should have MFA enabled and should not be used for routine email or web browsing. Where possible, each person should have their own account rather than sharing one login between a team.
Shared accounts create a practical headache as well as a security risk. If several people use one password, there is no clear record of who signed in, and an MFA code may be tied to one employee’s mobile phone. It is normally better to give people individual accounts and the right level of access for their role.
For charities and community groups, this can be tricky where volunteers change regularly. A straightforward joiner and leaver process helps: set up access and MFA before someone starts, then remove their account promptly when their role ends. It is a modest piece of administration that can prevent a serious incident later.
MFA is required, but it is not the whole standard
Cyber Essentials is designed around a set of basic technical controls. MFA is one part of the picture, alongside secure configuration, security updates, malware protection and user access control. Switching on MFA alone will not make an organisation Cyber Essentials ready.
For example, a laptop with an unsupported operating system may still cause a problem, even if every cloud account uses MFA. So can unmanaged devices, accounts with excessive permissions, default router passwords or software that has not been updated.
There is also a difference between meeting the minimum requirement and making a well-judged security improvement. Cyber Essentials does not necessarily prescribe MFA for every on-premise application or every type of remote connection in identical terms. Yet MFA for remote access, privileged accounts and sensitive systems is usually a very sensible step. The right approach depends on the systems you use, the information you hold and how your people work.
How to prepare without disrupting your team
The smoothest MFA roll-outs are planned around people, not just settings. Start by listing your cloud services and identifying every account that can access them. Include administrators and occasional users, not only the staff who sit at a desk every day.
Then choose an authentication method that your team can use confidently. An authenticator app is often inexpensive and familiar, but consider alternatives for staff who do not have a work mobile phone or who need accessibility support. Make sure there is a secure process for replacing a lost mobile phone, and keep recovery methods tightly controlled. Recovery codes should not be left in an inbox or written on a sticky note beside a monitor.
Before enforcing MFA across the organisation, test the process with a small group. Check that users can enrol, sign in from their usual devices and get help quickly if something goes wrong. A short, plain-English guide and a named person to contact can make the difference between a calm change and a frustrating Monday morning.
It is also wise to review old authentication methods. Some legacy email applications, printers or third-party tools may rely on basic username-and-password sign-in and stop working once MFA is enforced. That does not mean you should postpone MFA indefinitely. It means those tools need updating, replacing or configuring with a supported, secure method.
A practical Cyber Essentials MFA check
Before starting your assessment, be able to answer these questions with confidence:
- Which cloud services are in use across the organisation?
- Does every user account have MFA enabled where the service provides it?
- Are administrator and finance-related accounts protected and individually assigned?
- Do you have a safe process for lost devices, new starters and leavers?
- Have you checked for older apps or devices that may be relying on outdated sign-in methods?
If any answer is unclear, that is the point to investigate rather than guess on the questionnaire. Cyber Essentials is as much about understanding your setup as it is about ticking a box.
For organisations without an in-house IT team, this work can feel like another job added to an already busy week. A good IT partner can review the accounts, apply the right settings, explain the change in plain English and support staff through enrolment. Bees Knees IT helps West Yorkshire organisations take the sting out of Cyber Essentials preparation without turning it into a jargon-filled project.
MFA may add a few seconds to a sign-in, but it can stop a stolen password becoming a costly breach. Put it in place thoughtfully, support your people properly and it becomes a reassuring everyday habit rather than a hurdle.
Leave A Comment