Require MFA for all administrative access accounts, where supported, on all enterprise assets, whether managed on-site or through a service provider.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.008 | Network Provider DLL |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.007 | Hybrid Identity |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., hybrid identity environment admin, synchronization service, cloud tenant) to patch, modify, or otherwise backdoor cloud authentication processes
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.006 | Multi-Factor Authentication |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify MFA mechanisms and enable persistent access to compromised accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.005 | Reversible Encryption |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., domain/identity policy administrator, local security policy administrator) to abuse Active Directory encryption properties and gain access to credentials on Windows systems.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.004 | Network Device Authentication |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to bypass of native authentication mechanisms for tenant/device management accounts on network devices.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.003 | Pluggable Authentication Modules |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.002 | Password Filter DLL |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious password filter dynamic link libraries (DLLs) into the authentication process.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.001 | Domain Controller Authentication |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556 | Modify Authentication Process |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify authentication processes or mechanisms.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1110.004 | Credential Stuffing |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using credentials obtained from breach dumps to gain access to admin accounts through credential overlap.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1110.003 | Password Spraying |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using commonly used passwords to attempt to acquire valid admin credentials.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1110.002 | Password Cracking |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password cracking to recover admin credentials.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1110.001 | Password Guessing |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password guessing to access admin accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1110 | Brute Force |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from brute forcing admin credentials.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1072 | Software Deployment Tools |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to provide system and access isolation for critical network systems.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.009 | Conditional Access Policies |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify conditional access policies.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1078.004 | Cloud Accounts |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1078.003 | Local Accounts |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1078 | Valid Accounts |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1078.002 | Domain Accounts |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1098 | Account Manipulation |
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to maintain or elevate access using compromised credentials.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1599 | Network Boundary Bridging |
Comments
Using multi-factor authentication on accounts that administer network devices helps prevent adversaries from using compromised credentials to reconfigure or bypass network boundaries by limiting their ability to log in.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1601.002 | Downgrade System Image |
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to install older operating systems by limiting their ability to log in.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1601.001 | Patch System Image |
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to modify system images and introduce new capabilities or weaken defenses by limiting their ability to log in.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1601 | Modify System Image |
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to modify system images by limiting their ability to log in.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.004 | Network Device Authentication |
Comments
Requiring multi-factor authentication on administrator accounts ensures that adversaries cannot rely on a single implanted or backdoor password to gain access to network devices without also satisfying an independent second factor.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1098.005 | Device Registration |
Comments
Requiring multi-factor authentication (MFA) to register devices in Entra ID, configuring MFA systems to disallow enrolling new devices for inactive accounts, and using conditional access policies to restrict initial MFA device enrollment to trusted locations or devices reduces the success of adversary attempts to add additional devices to an adversary-controlled account.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1136.002 | Domain Account |
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1136.001 | Local Account |
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1136 | Create Account |
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1199 | Trusted Relationship |
Comments
Using multi-factor authentication for administrative accounts reduces the success of adversaries breaching trusted third party relationships to compromise those networks and gain access to intended victims.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1078.001 | Default Accounts |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1098.003 | Additional Cloud Roles |
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to add additional roles or permissions to an adversary-controlled cloud account to maintain or elevate access.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1098.002 | Additional Email Delegate Permissions |
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to grant additional permission levels to an adversary-controlled email account.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1098.001 | Additional Cloud Credentials |
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to add adversary-owned credentials to a cloud account to maintain or elevate access.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1136.003 | Cloud Account |
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1599.001 | Network Address Translation Traversal |
Comments
Using multi-factor authentication on accounts that administer network devices helps prevent adversaries from using compromised credentials to modify a network device’s Network Address Translation (NAT) configuration by limiting their ability to log in.
References
|