CIS Controls CIS-6.5

Require MFA for all administrative access accounts, where supported, on all enterprise assets, whether managed on-site or through a service provider.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-6.5 Require MFA for Administrative Access mitigates T1556.008 Network Provider DLL
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.007 Hybrid Identity
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., hybrid identity environment admin, synchronization service, cloud tenant) to patch, modify, or otherwise backdoor cloud authentication processes
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.006 Multi-Factor Authentication
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify MFA mechanisms and enable persistent access to compromised accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.005 Reversible Encryption
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., domain/identity policy administrator, local security policy administrator) to abuse Active Directory encryption properties and gain access to credentials on Windows systems.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.004 Network Device Authentication
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to bypass of native authentication mechanisms for tenant/device management accounts on network devices.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.003 Pluggable Authentication Modules
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.002 Password Filter DLL
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious password filter dynamic link libraries (DLLs) into the authentication process.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.001 Domain Controller Authentication
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556 Modify Authentication Process
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify authentication processes or mechanisms.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.004 Credential Stuffing
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using credentials obtained from breach dumps to gain access to admin accounts through credential overlap.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.003 Password Spraying
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using commonly used passwords to attempt to acquire valid admin credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.002 Password Cracking
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password cracking to recover admin credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.001 Password Guessing
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password guessing to access admin accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110 Brute Force
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from brute forcing admin credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1072 Software Deployment Tools
Comments
Implement multi-factor authentication (MFA) for administrative accounts to provide system and access isolation for critical network systems.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.009 Conditional Access Policies
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify conditional access policies.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1078.004 Cloud Accounts
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1078.003 Local Accounts
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1078 Valid Accounts
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1078.002 Domain Accounts
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1098 Account Manipulation
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to maintain or elevate access using compromised credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1599 Network Boundary Bridging
Comments
Using multi-factor authentication on accounts that administer network devices helps prevent adversaries from using compromised credentials to reconfigure or bypass network boundaries by limiting their ability to log in.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1601.002 Downgrade System Image
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to install older operating systems by limiting their ability to log in.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1601.001 Patch System Image
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to modify system images and introduce new capabilities or weaken defenses by limiting their ability to log in.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1601 Modify System Image
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to modify system images by limiting their ability to log in.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.004 Network Device Authentication
Comments
Requiring multi-factor authentication on administrator accounts ensures that adversaries cannot rely on a single implanted or backdoor password to gain access to network devices without also satisfying an independent second factor.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1098.005 Device Registration
Comments
Requiring multi-factor authentication (MFA) to register devices in Entra ID, configuring MFA systems to disallow enrolling new devices for inactive accounts, and using conditional access policies to restrict initial MFA device enrollment to trusted locations or devices reduces the success of adversary attempts to add additional devices to an adversary-controlled account.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1136.002 Domain Account
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1136.001 Local Account
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1136 Create Account
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1199 Trusted Relationship
Comments
Using multi-factor authentication for administrative accounts reduces the success of adversaries breaching trusted third party relationships to compromise those networks and gain access to intended victims.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1078.001 Default Accounts
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1098.003 Additional Cloud Roles
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to add additional roles or permissions to an adversary-controlled cloud account to maintain or elevate access.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1098.002 Additional Email Delegate Permissions
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to grant additional permission levels to an adversary-controlled email account.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1098.001 Additional Cloud Credentials
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to add adversary-owned credentials to a cloud account to maintain or elevate access.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1136.003 Cloud Account
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1599.001 Network Address Translation Traversal
Comments
Using multi-factor authentication on accounts that administer network devices helps prevent adversaries from using compromised credentials to modify a network device’s Network Address Translation (NAT) configuration by limiting their ability to log in.
References