What's stopping MFA?

The Authentication Insights Newsletter

Hello,

Welcome to The Authentication Insights Newsletter, where we share practical perspectives on identity and authentication in on-premises and hybrid Active Directory environments.

In this edition, we’ll focus on a deceptively simple problem: organizations may say they’re “using MFA,” but most aren’t using it everywhere.

That gap leaves credentials unprotected, attackers with opportunities, and IT teams with a false sense of security.

Ask any IT team, and the majority will say they’ve deployed MFA. But probe deeper and you’ll hear a different story: MFA is often only applied to certain accounts, certain users, or certain systems. This partial coverage creates blind spots that attackers exploit.

Recent breaches show how often a single unprotected account, a remote access point, or a SaaS login without MFA enabled, is enough to trigger compromise.

So why, despite widespread recognition of its importance, is MFA not consistently applied?

  1. MFA is a top-down technology; MFA started as a high-end security measure for governments and large enterprises. Its legacy is still with us: many vendors treat MFA as an add-on rather than a must-have, built-in feature. IT teams that want to extend MFA universally, especially in on-prem AD, often face complexity, middleware, and extra licensing costs. This slows down broad adoption.

  2. Optimism bias: Human nature is part of the problem. Many organizations operate under the assumption that “we’re probably fine.” A single uncovered account may not feel urgent, until it’s exploited. Attackers, however, are persistent, automated, and industrialized. They only need one gap, and partial MFA is still partial protection.

  3. User reluctance: MFA introduces friction. IT admins anticipate resistance from employees who see it as an extra step, or fear it will complicate workflows. While this perception is real, it can overshadow the far greater disruption caused by identity-based breaches. Usability concerns too often outweigh the security imperative.

The reality is clear: if MFA isn't everywhere, attackers will find the gaps.

Moving forward, IT teams must plan for MFA not as a nice-to-have add-on, but as a universal control that adapts to context, user roles, and evolving attack techniques.

This requires both organizational buy-in and hands-on guidance.

Educating users, making MFA as seamless as possible, and ensuring coverage from every credential, every account, are all key steps toward zero trust.

Explore deeper guidance on closing MFA gaps and improving day-to-day resilience:

Until next time,

The Authentication Insights Team