EU AI Act · Article 50 transparency obligations apply as of August 2, 2026.  Check your AI governance free →  ·  Article 50, checked — on ScrutinEyes

ScrutinEyes · 2026-07-26

The MFA Audit Checklist

Ten failure modes, one afternoon, zero feelings. Score what you can prove.

The dashboard showed 95% MFA adoption. Green across the board. The auditors found the service account three days later — full read access to every customer database, password authentication only, credentials sitting in a config file that had been committed to Git two years earlier. Nobody remembered creating it. The dashboard never counted it. (A composite scene: every detail is a recurring finding documented in published audits and breach reports — no single company is described.)

That gap is not exotic. It is the norm. This checklist is the companion to the full write-up on MFA deployment failure modes — ten gaps that recur in enterprise audit findings, distilled to what can be verified in one afternoon: https://scrutineyes.substack.com/p/mfa-deployment-failure-modes-what

One rule: a box only counts if it can be proven — with a log, a report, or a document. Not a feeling. Anything unprovable is a gap. Tally at the end.

1 · Service accounts

☐ A complete, current inventory of service accounts exists

☐ Privileged service accounts authenticate with certificates (mTLS), not passwords

☐ Integration accounts use API keys rotated every 60–90 days

☐ No service account credentials in config files or Git history — verified, not assumed

Red flag: “they’re automated, low-risk.” A service account with read access to every database is the highest-risk identity in the building.

2 · Factor strength

☐ The exact factor split is known: % SMS OTP / % app-based TOTP / % hardware keys

☐ Zero admin, finance, HR, or legal accounts on SMS or email OTP

☐ A dated, announced deprecation plan for SMS OTP exists

Red flag: SMS OTP as the default. SIM swaps are commodity attacks, and NIST 800-63B has recommended against SMS for years.

3 · Exemptions

☐ A report of every MFA-exempt account can be generated on demand

☐ Every exemption has a documented business reason and a compensating control

☐ No exemption older than 6 months without re-authorization

☐ Every legacy-system exemption carries a sunset date

Red flag: an exemption nobody remembers approving. That is not an exception — it is an open door with paperwork.

4 · Emergency bypass

☐ Every bypass mechanism is inventoried — break-glass, support override, all of them

☐ Bypass requires two admins, not one

☐ Every use, success and failure, is logged and alerts the CISO in real time

☐ Each use triggers a post-incident review within 24 hours

☐ Frequency stays under 5 uses per month

Red flag: “emergencies” three times a week. Routine bypass means the system design is broken, not the MFA.

5 · VPN and remote access

☐ VPN login enforces MFA before any network access is granted

☐ No separate RADIUS/LDAP path exists that skips it

Red flag: strong MFA on the app, nothing on the VPN in front of the entire network. Incident-response data consistently ranks compromised remote access — VPN and RDP — among ransomware’s top initial access vectors.

6 · Trusted devices

☐ Trusted-device window is 30 days or less

☐ Sensitive operations re-prompt even on trusted devices

☐ Departed employees’ device tokens are revoked — verified, not assumed

☐ High-risk accounts have trusted-device disabled entirely

7 · Layer coverage

☐ SSH to application servers requires MFA

☐ API access enforces MFA or equivalent strong auth

☐ Direct network access cannot bypass application-layer MFA

Red flag: MFA at one layer only. That is not defense in depth — it is a single point of failure with good PR.

8 · Backup codes

☐ Policy requires backup codes in a password manager — never email, never printed

☐ One set of codes per user, maximum

☐ High-risk accounts have no backup codes; recovery is a manual admin process

Red flag: ask 10 employees where their backup codes are. The answers will scare you.

9 · Privileged tiering

☐ Admins face stronger MFA than regular users, not identical requirements

☐ Privileged access requires hardware keys, or TOTP plus hardware combo

Red flag: the same MFA for the intern and the domain admin. Auditors scrutinize privileged authentication hardest for a reason.

10 · Monitoring

☐ ALL MFA events are logged — failures included, not just successes

☐ Logs reach the SIEM, with alerts for 10+ failures/hour, unusual-location failures, and privileged-account failures

☐ A weekly dashboard tracks success rate and failure patterns

Red flag: logging successes only. Attackers probe with failures — that is the half nobody watches.

Scoring

Count the unchecked boxes.

0–3 gaps: top tier. Document what exists; it will survive the audit and the attack.

4–8 gaps: typical enterprise. Priority order: service accounts and VPN (critical), weak factors and stale exemptions (high).

9+ gaps: the dashboard is lying. Pick one critical gap this week, estimate the effort, get leadership buy-in. The gaps are fixable — but only if someone looks.

Every box above maps to something an examiner will request under PCI DSS v4, SOC 2, NYDFS Part 500, or HIPAA’s proposed 2026 update. The full article carries the mapping, remediation timelines, and audit-defense language for each failure mode.

If this checklist found gaps the dashboard never showed, subscribe — the weekly brief covers what’s coming before it hits the audit.

Sources

PCI DSS v4.0 Requirement 8, MFA for all CDE access (effective March 2025) — PCI Security Standards Council: https://www.pcisecuritystandards.org/

NIST SP 800-63B, Digital Identity Guidelines — SMS OTP as a restricted authenticator: https://pages.nist.gov/800-63-3/sp800-63b.html

NYDFS Cybersecurity Regulation, 23 NYCRR Part 500 — MFA requirements: https://www.dfs.ny.gov/industry-guidance/cybersecurity/multifactor-authentication

HHS HIPAA Security Rule NPRM — proposed mandatory MFA for ePHI access: https://www.hipaajournal.com/hipaa-updates-hipaa-changes/

Ransomware initial-access data, VPN/RDP among top vectors: https://www.halcyon.ai/blog/rdp-and-vpn-remain-top-ransomware-attack-pathways and https://blog.talosintelligence.com/ir-trends-q1-2026/

Reading this because someone's asking about your security? See exactly which rules apply to you and where you stand — check your readiness free. Five minutes, in your browser, nothing stored unless you ask. Readiness, not legal advice.