Understanding the Digital Operational Resilience Act (DORA) MFA requirement

Here's what IT teams managing Active Directory need to know about DORA's MFA mandate, and how to meet it without changing infrastructure.

Updated July 24, 2026
Digital Operational Resilience (DORA) MFA requirement

The Digital Operational Resilience Act (DORA) is a European Union (EU) regulation designed to strengthen cyber resilience of digital systems in the financial sector. Part of Europe’s push for tighter cybersecurity measures, one standout requirement is stronger user authentication through multi-factor authentication (MFA).

If you’re managing an Active Directory (AD) environment in that space, here’s what you need to know about DORA’s MFA requirement, some AD integration challenges you may face, and how UserLock can simplify compliance. 


Understanding DORA’s MFA requirement

First, let's break down DORA’s MFA requirement and show you how UserLock can help you achieve DORA compliance without adding management overhead or rewiring infrastructure.

MFA under Article 9

In Article 9.4 DORA emphasizes "strong authentication." In practice, DORA's aim is for EU financial entities and their ICT providers to:

  • Implement at least two factors to verify user logins (for example, something you know, something you have, or something you are).

  • Prioritize MFA for high-risk access or privileged accounts.

  • Continuously monitor user authentication to address threats as they evolve.

DORA has been in full effect since 17 January 2025. Enforcement has since moved from readiness checks to active review, and supervisory authorities are now examining for compliance evidence, not plans. Financial entities that don't meet these requirements can face fines of up to 2% of annual worldwide turnover or or €10 million (whichever is higher), with individual senior managers personally liable for up to €1 million.

UserLock MFA for DORA

Apply MFA granularly across workstation, RDP, RD Gateway, VPN, IIS, and SaaS.

Why MFA is critical for the EU financial sector

Mitigating credential-based attacks

Passwords alone are not enough to protect access to user accounts. From phishing scams to credential stuffing, attackers have countless ways to obtain or crack simple credentials. By enforcing multi-factor authentication, you immediately strengthen your frontline defense, forcing attackers to bypass multiple security barriers instead of just one.

Enhancing operational resilience

One compromised account can trigger a chain reaction, disrupting services and undermining confidence in your organization. MFA helps you:

  • Minimize downtime: Fewer successful breaches mean fewer crises to manage.

  • Safeguard ICT systems: Only verified individuals can modify essential systems or access sensitive information.

Aligning with regulatory obligations

Because DORA specifically mentions stronger authentication, MFA is no longer just a best practice for the EU's financial sector, it’s a hard requirement with consequences for noncompliance. By deploying MFA systematically, you can directly address Article 9's "strong authentication" requirement and demonstrate a proactive approach to protecting critical infrastructure.

Common challenges when implementing MFA for DORA

Balancing user experience with security

Overly complex or slow authentication methods can frustrate users and disrupt productivity. You need an MFA solution that’s both effective and user-friendly, ensuring better adoption rates and minimal friction for employees.

Integrating with complex IT environments

Financial institutions typically rely on a patchwork of legacy systems, cloud platforms, and third-party applications. Making all these systems work well with MFA requires careful planning, robust APIs or connectors, and centralized policy enforcement.

Handling scalability and performance

When thousands of users login simultaneously every day, your authentication service must handle peak demand without lag. Poorly performing systems can slow down critical operations and undermine user confidence in security controls.

Meeting tight compliance timelines

With DORA’s application date in the rearview mirror, organizations looking to implement MFA for the first time or roll it out across all users need to act quickly.

How UserLock helps meet DORA’s MFA requirement

UserLock adds the centralized access management and MFA that Active Directory lacks natively.

Built for on-premises or hybrid AD environments, UserLock allows you to combine MFA with contextual access controls on:

  • Who can log on (based on AD users, groups, and OUs).

  • Where they can log on (workstations, servers, remote connections, IP address, geolocation).

  • When they can log on (enforce time-based rules).

  • Concurrent session limits to minimize attack surface and help prevent lateral movement.

Centralized MFA policy enforcement

With UserLock, you can define granular MFA policies for all users, both privileged and non-privileged.

IT keeps full control over MFA application with the ability to set customized MFA rules and frequency.

Set policies on existing Active Directory entities:

Apply MFA granularly by session and connection type, and adjust frequency to match risk:

Access policies MFA user

This centralized, granular approach ensures consistency and allows you to implement security without frustrating your end users (or IT!).

Flexible MFA methods

With UserLock, IT can choose up to two authentication methods to accommodate different risk profiles and user preferences, including:

  • Push notifications

  • Authenticator apps

  • Hardware tokens or keys for the gold standard in phishing-resistant MFA

With the option to choose up to two MFA methods per user, IT can tailor security levels to user roles and systematically implement DORA Article 9 requirements across all users.

Real-time session monitoring and responses

With UserLock, IT can monitor user sessions in real time and can remotely respond to suspicious activity.

Logoff or block users to stop suspicious access and prevent lateral movement:

Active sessions - Active Directory

IT can set up and receive custom alerts. This helps keep teams from drowning in noise, and allows different members of the team to receive different alerts.

Configure custom alerts & notifications:

Alerts & notifications - logon denied

These features align with DORA’s focus on continuous monitoring and rapid containment of security incidents.

Scalable across multi-site or enterprise deployments

Whether you manage a small user base or thousands across multiple sites, AD admins appreciate how easily UserLock is to implement, thanks to its close AD integration.

Plus, with in-platform visibility across your AD users, groups, and OUs, you can quickly spot policy implementation gaps.

Comply with DORA's MFA requirement

DORA's strong authentication requirement exists because credential-based attacks on financial systems are a direct threat to operational resilience (exactly what the regulation is designed to protect). Article 9 mandates MFA as a baseline control, backed by continuous monitoring and the ability to respond to suspicious access in real time.

UserLock helps IT teams running on-prem and hybrid Active Directory meet that requirement with granular MFA policies, real-time session monitoring, concurrent session limits, and centralized access controls that deploy simply on top of your existing AD environment.

XFacebookLinkedIn

francois-amigorena-headshot

François Amigorena

President and CEO, IS Decisions

François Amigorena is the founder of IS Decisions, a global software company specializing in access management and MFA for Microsoft Windows and Active Directory. He is a frequently published author on topics like Zero Trust architecture, insider threats, password policies, and user security awareness.