The practical starting point
Not all multifactor methods provide the same protection against deceptive sign-in attempts. CISA encourages stronger approaches, including phishing-resistant methods where available. The available choices depend on the actual service and the organisation’s access needs.
A workable next step
Compare official service documentation rather than assuming that every second step is equivalent. Record supported methods, recovery arrangements and practical constraints for authorised users. Do not downgrade protection to make a demonstration easier. A useful decision note explains the chosen method and its limitations without presenting it as a guarantee against every possible account incident.
Keep in your notes
- Check supported methods.
- Include recovery needs.
- Record limitations honestly.
