Identity Management - Phishing-Resistant MFA Coverage¶
Description¶
The percentage of active user accounts with a phishing-resistant multi-factor authentication method enrolled, protecting accounts against adversary-in-the-middle phishing and push fatigue attacks that defeat one-time codes and push notifications.
How we measure it¶
Find all active Okta users and their enrolled authentication factors. Users are considered compliant if at least one active factor is phishing-resistant: Okta FastPass (signed_nonce) or WebAuthn (security keys, passkeys and platform authenticators such as Touch ID or Windows Hello).
Meta Data¶
| Attribute | Value |
|---|---|
| Metric id | im_phishing_resistant_mfa |
| Category | Identity Management |
| SLO | 80.00% - 95.00% |
| Weight | 0.5 |
| Type |
References¶
| Framework | Ref | Domain | Control |
|---|---|---|---|
| ISO 27001:2022 | A.8.5 | 8 Technological controls | Secure authentication |
| CIS 8.1 | 6.3 | Access Control Management | Require MFA for Externally-Exposed Applications |
| CIS 8.1 | 6.5 | Access Control Management | Require MFA for Administrative Access |
| NIST CSF v2.0 | PR.AA-03 | Identity Management, Authentication, and Access Control (PR.AA) | PR.AA-03: Users, services, and hardware are authenticated |
| Essential8-ML2 | ISM-1682 | Multi-factor authentication | Multi-factor authentication used for authenticating users of systems is phishing-resistant. |
| Essential8-ML3 | ISM-1682 | Multi-factor authentication | Multi-factor authentication used for authenticating users of systems is phishing-resistant. |
| Essential8-ML2 | ISM-1872 | Multi-factor authentication | Multi-factor authentication used for authenticating users of online services is phishing-resistant. |
| Essential8-ML3 | ISM-1872 | Multi-factor authentication | Multi-factor authentication used for authenticating users of online services is phishing-resistant. |
Code¶
SELECT
users.profile_login AS resource,
'user' AS resource_type,
CASE WHEN count(factors.id) FILTER (WHERE factors.factor_type IN ('signed_nonce', 'webauthn')) > 0 THEN 1 ELSE 0 END AS compliance,
CASE
WHEN count(factors.id) = 0 THEN 'No active MFA factor'
WHEN count(factors.id) FILTER (WHERE factors.factor_type IN ('signed_nonce', 'webauthn')) > 0
THEN 'Phishing-resistant factor enrolled (' || string_agg(DISTINCT factors.factor_type, ', ') || ')'
ELSE 'Only phishable factors enrolled (' || string_agg(DISTINCT factors.factor_type, ', ') || ')'
END AS detail
FROM {{ ref('okta_users') }} AS users
LEFT JOIN {{ ref('okta_user_factors') }} AS factors
ON factors.user_id = users.id
AND factors.status = 'ACTIVE'
WHERE users.status = 'ACTIVE'
GROUP BY users.profile_login