Skip to content

Identity Management - Phishing-Resistant MFA Coverage

Description

The percentage of active user accounts with a phishing-resistant multi-factor authentication method enrolled, protecting accounts against adversary-in-the-middle phishing and push fatigue attacks that defeat one-time codes and push notifications.

How we measure it

Find all active Okta users and their enrolled authentication factors. Users are considered compliant if at least one active factor is phishing-resistant: Okta FastPass (signed_nonce) or WebAuthn (security keys, passkeys and platform authenticators such as Touch ID or Windows Hello).

Meta Data

Attribute Value
Metric id im_phishing_resistant_mfa
Category Identity Management
SLO 80.00% - 95.00%
Weight 0.5
Type risk

References

Framework Ref Domain Control
ISO 27001:2022 A.8.5 8 Technological controls Secure authentication
CIS 8.1 6.3 Access Control Management Require MFA for Externally-Exposed Applications
CIS 8.1 6.5 Access Control Management Require MFA for Administrative Access
NIST CSF v2.0 PR.AA-03 Identity Management, Authentication, and Access Control (PR.AA) PR.AA-03: Users, services, and hardware are authenticated
Essential8-ML2 ISM-1682 Multi-factor authentication Multi-factor authentication used for authenticating users of systems is phishing-resistant.
Essential8-ML3 ISM-1682 Multi-factor authentication Multi-factor authentication used for authenticating users of systems is phishing-resistant.
Essential8-ML2 ISM-1872 Multi-factor authentication Multi-factor authentication used for authenticating users of online services is phishing-resistant.
Essential8-ML3 ISM-1872 Multi-factor authentication Multi-factor authentication used for authenticating users of online services is phishing-resistant.

Code

SELECT
  users.profile_login AS resource,
  'user' AS resource_type,
  CASE WHEN count(factors.id) FILTER (WHERE factors.factor_type IN ('signed_nonce', 'webauthn')) > 0 THEN 1 ELSE 0 END AS compliance,
  CASE
    WHEN count(factors.id) = 0 THEN 'No active MFA factor'
    WHEN count(factors.id) FILTER (WHERE factors.factor_type IN ('signed_nonce', 'webauthn')) > 0
      THEN 'Phishing-resistant factor enrolled (' || string_agg(DISTINCT factors.factor_type, ', ') || ')'
    ELSE 'Only phishable factors enrolled (' || string_agg(DISTINCT factors.factor_type, ', ') || ')'
  END AS detail
FROM {{ ref('okta_users') }} AS users
LEFT JOIN {{ ref('okta_user_factors') }} AS factors
  ON factors.user_id = users.id
  AND factors.status = 'ACTIVE'
WHERE users.status = 'ACTIVE'
GROUP BY users.profile_login