Organization MFA requirement disabled
ID |
mfa_disabled |
Severity |
critical |
Resource |
Organization |
Description
Detects whether the MFA requirement has been disabled.
Two alternatives are considered:
-
When feature is available, MFA policy changes are reported on real time.
-
As a fallback, a scheduled task performs regular checks against API looking for MFA policy transitions from enabled to disable.
Impact
Not enforcing multifactor authentication can have a wide range of negative impact on an organization. Here are some examples:
-
Security Breach: Without multifactor authentication, attackers may be able to gain access to the organization’s systems or sensitive data by stealing or guessing passwords, leading to data breaches, financial losses, or reputational damage.
-
Compliance Issues: Not enforcing multifactor authentication can violate regulatory or compliance requirements, exposing the organization to legal liabilities, fines, or other penalties.
-
Reduced Accountability: Without multifactor authentication, it can be difficult to track who made what changes to the organization’s systems or data, reducing accountability and transparency.
-
Reputation Damage: A security breach resulting from not enforcing multifactor authentication can damage the organization’s reputation, leading to loss of customers, investors, or business partners.
-
Operational Disruptions: A security breach resulting from not enforcing multifactor authentication can disrupt the organization’s development and operations workflow, leading to downtime, delays, or other negative impacts.