Strong authentication routine
What is a practical strong-authentication routine?
A practical strong-authentication routine combines a unique credential, the strongest suitable multifactor method available, protected recovery routes, separate administrative access, and a repeatable process for enrollment, loss, replacement, and removal.
What the business should be able to see
- Start with email, domain registration, finance, payroll, file storage, remote access, and administrator accounts.
- Use a business-approved password manager and prefer phishing-resistant multifactor authentication when the account supports it.
- Protect recovery email, phone, codes, devices, and backup administrators as carefully as the primary sign-in.
What this definition cannot establish
- Multifactor authentication reduces some account-takeover risk but does not prevent every phishing, recovery, malware, session, or administrator failure.
- The strongest usable method depends on the account, people, devices, recovery needs, and consequences of lockout.