Skip to content

Home Expertise / Identity & access

IAM / IAM-03

MFA, passkeys and stronger authentication

Strengthening sign-in with additional factors or phishing-resistant methods while governing account recovery.

WHEN IT HELPS

A focused response
to a defined need.

CISO or CIO; sensitive accounts, remote access, customer requirements or stolen passwords.

AT A GLANCE

Family
Identity & access

Engagement
Implementation

Reference
IAM-03

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Pilot population
  • method selection
  • staged rollout, emergency rules, recovery and removal of lost factors

Deliverables

  • Authentication policy
  • configured profiles
  • user guide and recovery tests

Acceptance evidence

Normal sign-in, lost-factor recovery, onboarding and offboarding are tested; exceptions have an owner and duration.

DELIVERY

How the work is structured.

Approach

Inventory identities and applications; define roles and policies; pilot with one group; test allow/deny/recovery paths; roll out and hand over.

Prerequisites & responsibilities

Customer: application owners, HR, administrators, pilot groups and emergency accounts. Provider: design, integration and testing within agreed permissions.

Scope factors

Users, directories, applications, protocols, privileged accounts, compatibility and migration. Licenses, physical keys and recurring operations are separate.

Questions to clarify

Which uses and devices? Which accounts are critical? Who can reset factors and on what evidence?

IMPORTANT BOUNDARIES

Not every MFA method offers the same phishing resistance; weak recovery can undermine the benefit.

Recovery and emergency access are tested before rollout. Authentication, authorisation and privileged-access management are complementary layers.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A professional firm reuses email passwords. Project: pilot MFA and roll it out. Target outcome: stronger access and prepared support; incompatible service accounts receive separate treatment.

Scenario 02

Administrators need phishing resistance. Project: test security keys or passkeys compatible with their applications. Target outcome: stronger protection for sensitive accounts and an audited recovery process; compatibility is not assumed.

Technology and reference context

FIDO2/WebAuthn, security keys and methods supported by the chosen IAM platform.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.