Multi-factor authentication (MFA) has long been one of the Essential Eight mitigation strategies, but the bar for acceptable MFA has moved. The Australian Signals Directorate's (ASD) November 2023 update to the Essential Eight Maturity Model (E8MM) tightened MFA requirements at Maturity Level Two (ML2) and Maturity Level Three (ML3), ending reliance on weaker MFA for organisations targeting those levels. For Australian IT and security leaders managing Essential Eight uplift programs, this changes both the technical roadmap and the assessment conversation with auditors. This article explains what changed, why it matters, and what a practical remediation path looks like.
What Changed in the November 2023 Update
The Essential Eight comprises eight mitigation strategies, including patching applications, patching operating systems, MFA, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening and regular backups. The E8MM, first published in June 2017, is reviewed and updated annually to stay aligned with current tradecraft.
The November 2023 revision made two specific MFA changes that IT and security leaders should note. First, a requirement was added that MFA used for authenticating users of systems is phishing-resistant, closing an approach that had previously allowed organisations at lower maturity levels to opt out of stronger MFA in favour of weaker password-based authentication. Second, a new requirement was introduced for users to authenticate to their workstations using a form of phishing-resistant MFA, such as smart cards, security keys or Windows Hello for Business, with this change affecting ML2 and ML3.
ASD has been explicit about the reasoning: increasing maturity of standards such as FIDO2 and WebAuthn, rising real-time phishing and social engineering attacks against weaker MFA implementations, and comparable policy shifts among ASD's international partners all supported requiring phishing-resistant MFA at a lower maturity level than before. Phishing-resistant MFA under the model is defined by method rather than brand, requiring a combination of something the user has and something they know, or something they have that is unlocked by something they know or are.
Why This Matters for Risk and Assurance
This is not a cosmetic change. Under the current FAQ guidance, if an organisation relies on risk acceptance or risk transfer, such as cyber insurance, instead of implementing an entire mitigation strategy like MFA, that strategy is assessed as not implemented and the organisation's overall Essential Eight rating falls to Maturity Level Zero. Weak or optional MFA is not a compensating control leaders can substitute their way around when ML2 or above is the stated target.
For organisations already reporting ML2 or ML3, this creates an assurance gap if workstation logon or application authentication still rely on SMS codes, push notifications without number matching, or other phishing-susceptible methods. Boards relying on Essential Eight self-assessments should expect this gap raised in the next assessment cycle, and procurement arrangements referencing Essential Eight targets may need updated evidence.
Practical Steps for Uplift Programs
Meeting the updated requirement means moving beyond app-level MFA prompts and addressing device logon as well. Recommended actions include:
- Inventory current authentication methods across both application sign-in and device logon, distinguishing phishing-resistant methods (smart cards, security keys, certificate or key-based passwordless sign-in) from phishing-susceptible methods (SMS, voice calls, basic push approval).
- Prioritise privileged and remote-access accounts first, since these carry the greatest impact if compromised, before extending phishing-resistant MFA across the broader workforce.
- Plan for exceptions and legacy systems that cannot support phishing-resistant methods, and document these as time-bound exceptions with an accountable owner, consistent with ASD's compensating control approach.
- Coordinate identity, endpoint and helpdesk teams, since workstation logon changes touch device provisioning, break-glass account procedures and user support processes, not just the identity platform.
- Consider implementing phishing-resistant methods even at ML1 where practical. ASD's own guidance notes organisations should not be penalised for implementing more robust controls than a given maturity level requires, and doing so once can avoid a later, disruptive replacement project.
Accountability typically sits jointly with identity and access management leads and the CISO's uplift program, with endpoint and service desk teams as key dependencies for rollout.
Common Failure Modes and Evidence of Success
A common failure mode is treating this purely as an application sign-in problem and overlooking workstation logon, which was explicitly called out in the November 2023 change. Another is assuming existing push-based MFA already qualifies as phishing-resistant when it does not meet the defined criteria. A third is under-resourcing the exceptions register, leaving assessors unable to see how unsupported systems are managed.
Evidence that demonstrates progress includes a documented inventory of authentication methods by system and user population, a rollout plan and completion metrics for phishing-resistant workstation logon, and an exceptions register with named owners and review dates. These artefacts also directly support any independent Essential Eight assessment against the current maturity model.
Key Takeaway
The November 2023 Essential Eight update removed the option to rely on weaker MFA at ML2 and above and extended the phishing-resistant requirement to workstation logon, not just application sign-in. Organisations targeting ML2 or ML3 should treat this as a mandatory gap to close, not a future enhancement. The immediate next action is to inventory current authentication methods across both applications and device logon, identify where phishing-susceptible methods remain in use, and build a prioritised, evidenced rollout plan starting with privileged and remote-access accounts.
