Strategies for implementing MFA
The list of strategies in this section will provide suggestions that can help in a successful MFA implementation. As we discussed, each strategy needs to be considered according to business needs and as a balance between usability and security, as well as the costs involved. Also, security is a business issue, and a major initiative such as the implementation of an MFA system can only be successful with the support from high-level sponsors in the organization. It will be very difficult to succeed if it is just an IT or security team-imposed solution. In the following sections, I will also identify when the strategies and tips apply only to the workforce or only to customer MFA.
Eliminating passwords should be the goal
Even for small companies like Acme, it may be impossible to completely eliminate the use of passwords for all users accessing the organization’s internal applications. This can be due to a number of factors, such as the lack...