by Heath Gieson Years ago, I worked with a client to implement multi‑factor authentication across their organization. As part of the project, they gave us a list of users who required MFA and explained that this represented all the active users in the business. That sounded reasonable, so we implemented MFA exactly as scoped and closed the project. A few months later, they experienced an account compromise. The compromised account belonged to someone who had not worked at the company...














