Amazon iconAmazonSep 23, 2026 ~3 min source read

Why Australia’s MFA push matters and how AWS put MFA into practice

The Australian Signals Directorate’s “Switch it on” campaign urges everyone to enable multi-factor authentication. AWS summarizes why MFA remains one of the highest-impact controls, the steps it took to enforce MFA for root accounts, and practical next steps for organizations and individuals.

Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever

Share this story

Send the public story page.

Useful takeaways from this story.

MFA blocks over 99% of password-related attacks and is a low-cost, high-impact control for accounts and services.

AWS completed enforcement of MFA for root users across all account types in June 2025 after a phased rollout beginning in May 2024.

Phishing-resistant options such as FIDO2 passkeys and FIDO-certified security keys are available at no extra cost on AWS.

Directorate (ASD) launched a Multi-factor authentication: Switch it on campaign asking businesses, organisations, and individuals to enable MFA across online accounts. AWS endorses the campaign and frames MFA as a simple, effective control against credential-focused attacks such as phishing and credential stuffing.

Passwords alone are routinely targeted by attackers through phishing, credential stuffing, and social engineering. AWS cites that MFA prevents over 99 percent of password-related attacks. Because MFA requires an additional authentication factor, attackers who obtain or guess a password still cannot access the account unless they also bypass the second factor.

AWS implemented MFA enforcement for root users across all account types in June 2025. That rollout followed distinct phases:

  • May 2024: Required MFA for AWS Organizations management account root users.
  • June 2024: Expanded requirement to standalone account root users.
  • November 2024: Introduced centralized root access management.
  • June 2025: Completed enforcement across member accounts and all account types.

AWS describes this as the first comprehensive enforcement among major cloud providers and frames the milestone as evidence that organizations of any size can make MFA the standard configuration rather than an optional setting.

Available phishing-resistant options

AWS supports FIDO2 passkeys and FIDO-certified security keys for phishing-resistant authentication. Those methods reduce the effectiveness of real-time phishing and relay attacks because they rely on cryptographic attestations rather than shared codes or push approvals.

A compromise of an email or collaboration account can be used to reset credentials for cloud accounts. Source control breaches can expose secrets used to access infrastructure. AWS recommends enabling MFA on email, collaboration tools, source control systems, and any other services that support it. The ASD campaign page is cited as a broader source of guidance for non-AWS services.

AWS enforces MFA automatically for root users, so the immediate priority for teams is to enforce MFA for daily-use identities. AWS suggests configuring MFA for IAM users through the AWS Management Console and points to IAM security best practices for step-by-step actions. For organizations seeking phishing-resistant options, AWS points to documentation on passkeys and security keys in IAM.

  • Audit all accounts you control (email, cloud consoles, collaboration, source control). Enable MFA where supported.
  • Prioritize phishing-resistant methods (FIDO2 passkeys or FIDO-certified keys) where available.
  • For AWS customers, verify root users have MFA enforced, then roll out MFA for IAM users and service accounts.
  • Treat account recovery processes as an attack surface: ensure helpdesk and recovery flows require robust verification.

AWS links to its security resources and invites questions via comments or AWS re:Post. The post explicitly supports the ASD campaign and aggregates AWS security references for teams looking to align their configurations with the guidance.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app