Cloud File Sharing Security: Zero Trust, Monitoring and Future Cloud Risks
Explore how Cloud File Sharing Security uses Zero Trust, monitoring, SSPM and advanced cloud protection strategies to manage future security risks.
Multi-factor authentication (MFA) is a sign-in process that requires a user to verify their identity using two or more separate methods before access is granted. Typically, this means a password combined with something else — a code from an app, a prompt on a phone, or a physical security key.
It matters because a password alone is no longer considered proof that the right person is signing in. Passwords get reused, phished, and leaked in bulk, and MFA is the layer that catches an attacker even when they have the correct one. MFA rarely works in isolation, though — it's usually one part of a wider conditional access policies that also checks device health, location, and sign-in risk before granting access.
The gap between organisations with MFA enabled and those without is one of the starkest figures in identity security. Phishing-resistant multi-factor authentication can stop over 99% of identity-based attacks, even when an attacker already has a valid username and password, according to Microsoft's Digital Defense Report.
Yet adoption hasn't caught up with that figure. Workforce MFA adoption reached 70% of users as of January 2025, according to Okta's Secure Sign-in Trends Report. That leaves roughly three in ten user accounts — across a typical organisation — protected by a password alone.
The gap tends to concentrate in predictable places: shared mailboxes, service accounts, contractor logins, and users who were never re-prompted to enrol after their first sign-in. These accounts often go unnoticed in a security review because they're not part of the standard onboarding checklist, even though they carry the same access as any other account.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) lists MFA as one of its core recommended cyber hygiene practices, specifically calling out phishing-resistant methods — such as FIDO2 security keys or certificate-based authentication — as the strongest tier.
NIST's Digital Identity Guidelines (SP 800-63B) go further, defining specific "authenticator assurance levels" that distinguish between MFA methods. Not all MFA is treated equally under this framework: a one-time code sent by SMS sits at a lower assurance level than a hardware security key, because SMS can be intercepted or redirected through SIM-swapping.
For organisations handling sensitive data, this distinction matters in practice. Enabling MFA in a basic form satisfies a checkbox. Enabling MFA at a level that meets recognised assurance standards is a different — and more defensible — position if access is ever questioned during an audit or after an incident.
MFA on its own, however, only protects the moment of sign-in. What happens afterwards — whether that session stays valid for hours, whether it's re-checked if the user's location changes, whether a compromised account can still reach sensitive files — depends on conditional access policies working alongside MFA.
Understanding MFA is a useful starting point, but knowing which method to require, for which accounts, and under which conditions is where most organisations get stuck. Our SaaS Security for Microsoft 365 and Google Workspace course covers exactly this — how to configure MFA enforcement correctly across both platforms, and how to close the gaps that a 70% adoption rate usually represents.

A phased rollout works better than an all-at-once switch, and the order matters. Privileged accounts — global admins, security admins, anyone with access to billing or directory settings — should be enrolled first, since these are the accounts attackers target hardest and the ones where a compromise causes the most damage.
Standard users come next, ideally in small groups rather than the whole organisation at once. This makes it possible to catch problems — a department that relies on a shared device, for example, or an app that doesn't support modern authentication — before they affect everyone.
Shared mailboxes and service accounts need a different approach entirely. Many can't use an authenticator app in the normal sense, since no one person "owns" the sign-in. These accounts often need to be moved to certificate-based authentication, app passwords scoped tightly to a single purpose, or removed from interactive sign-in altogether if they don't need it.
Communication before enforcement reduces help-desk load significantly. Users who understand why MFA is being introduced, and who have already enrolled a method before it's required, generate far fewer "I'm locked out" tickets than users who encounter the prompt for the first time during enforcement.
Running the policy in report-only mode first the same approach recommended for conditional access policies generally shows exactly who would be affected and how, before anyone is actually blocked. Pairing this rollout with strong identity and access management practices, such as role-based scoping and regular exclusion-list reviews, keeps enforcement predictable rather than disruptive.

Two-factor authentication is a specific type of MFA that uses exactly two verification methods, most commonly a password plus a code or prompt. Multi-factor authentication is the broader term and can involve two or more methods, including combinations like a password, a security key, and a biometric check.
In practice, most organisations implement 2FA when they say they're "doing MFA," since two factors are enough to meet most security requirements. The distinction becomes more relevant for high-privilege accounts, where a third factor such as a hardware key in addition to a password and an app prompt may be required under stricter internal policies.
Yes, though it's far harder than bypassing a password alone. The most common methods are MFA fatigue — repeatedly sending prompts until a user approves one out of frustration — and adversary-in-the-middle attacks, where a fake login page captures both the password and the MFA code in real time.
Phishing-resistant methods, such as FIDO2 security keys and passkeys, are specifically designed to resist both of these techniques, because they're tied to the legitimate website and can't be replayed elsewhere. This is why standards bodies like CISA recommend phishing-resistant MFA as the strongest available tier, rather than treating all MFA methods as equivalent.

If MFA is one part of your organisation's identity strategy, conditional access policies are what tie it together with device checks, session limits, and risk-based rules.
Our SaaS Security for Microsoft 365 and Google Workspace course walks through both, with hands-on configuration steps for real tenants.