NIST SP 800-53 Rev. 5 · Identification and Authentication
IA-2(1) — Multifactor Authentication to Privileged Accounts
Privileged access without multifactor authentication. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.
Why this matters
An administrator who can sign in with a password alone
A second step at sign-in — a code from a phone, a hardware key, a fingerprint — is the single most effective defence against stolen passwords, and it matters most for the accounts that can change everything. Organizations frequently enable it broadly but leave gaps: an emergency account, a contractor, a service that was set up before the policy existed. The gap is invisible until someone finds it.
Why this check earns its place. It looks specifically at the accounts where a stolen password does the most damage, rather than reporting a general adoption percentage that hides exactly the wrong exceptions.
- What it reads
- The organization's list of who holds administrative roles, compared against its record of who has a second sign-in step enrolled.
- What it reports
- Accounts with administrative powers that can still be accessed with a password and nothing else.
See related public disclosures on the Signals page →
The requirement
The organization must implement multifactor authentication for access to privileged accounts.
NIST SP 800-53 Rev. 5 — IA-2(1).
NIST states the requirement without qualification for privileged accounts. What counts as privileged, which methods satisfy the requirement, and how exceptions are recorded remain organization-defined.
What a check finds
Privileged identity with no MFA enrolled, or observed authenticating with a single factor.
Choose your platform
CISA performance goals
- 3.F — Implement multifactor authentication (MFA)
What a result does not prove
Absence of MFA in one data source does not establish that no second factor exists. Registration state, enforcement policy, and observed behaviour are three different things and should be reconciled.