Access control
Is multi-factor authentication (MFA) required for all users?
How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.Expert answer
Require MFA for all internal users, especially for administrative and production access, and offer or enforce it for customer accounts. Prefer phishing-resistant methods such as hardware keys or authenticator apps over SMS.What the security reviewer is checking
The operative word is "required" — reviewers are hunting for the gap between MFA being available and MFA being enforced with no opt-out. They probe scope: does the requirement cover every employee, contractors, administrative and privileged accounts, VPN and remote access, and break-glass accounts? They also increasingly grade factor quality, preferring phishing-resistant methods like FIDO2 hardware keys or platform passkeys over SMS codes, which NIST SP 800-63B treats as a weaker channel. Expect scrutiny of exception handling: how a lost device is recovered without socially engineering your help desk.Example response you can adapt
This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.Yes, MFA is mandatory for all workforce accounts with no opt-out. Enforcement is centralized in our identity provider, which requires a second factor on every corporate application, our cloud consoles, VPN access, and the production environment. Approved factors are FIDO2 hardware security keys and platform authenticator passkeys, with a TOTP authenticator app as fallback; SMS and voice codes are not permitted. Privileged and administrative access additionally requires a phishing-resistant factor specifically. Contractors and temporary staff are held to the same policy through the same IdP. Device-loss recovery requires identity verification by the IT team on a live video call before a factor reset, and every reset is logged and reviewed. Compliance is monitored continuously; an account without a registered second factor cannot complete login.
Evidence reviewers expect you to attach
- Access control or authentication policy stating the MFA requirement and approved factors
- IdP configuration screenshot showing the MFA enforcement rule applied to all users
- MFA enrollment coverage report (percentage of active accounts with registered factors)
- SOC 2 report section on logical access controls (CC6.1)
- Factor-reset / account-recovery procedure documentation
Follow-up questions reviewers ask next
- Are SMS one-time codes allowed anywhere, and if so where?
- Is MFA enforced on programmatic and service-account access, or only interactive login?
- How do you prevent MFA fatigue / push-bombing attacks?
- What is the account recovery process when an employee loses their factor?
- Do customer-facing accounts also support or require MFA?
Answer every security questionnaire in minutes
Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demoRelated access control questions
What is your password policy?How do you handle employee offboarding?Do you perform background checks on employees?How do you manage access to production systems?Do you support single sign-on (SSO) for customers?How do you manage admin account security?
Browse the full security questionnaire question library