Under active development Content is continuously updated and improved

6.3Require MFA for Externally-Exposed Applications

IG1
IG2
IG3
Users
Protect

>Control Description

Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported. Enforcing MFA through a directory service or SSO provider is a satisfactory implementation of this Safeguard.

>Cross-Framework Mappings

>Relevant Technologies

Technology-specific guidance with authoritative sources and verification commands.

Ask AI

Configure your API key to use AI features.