CIS IG1 Safeguard 6.5: Require MFA for Administrative Access by Heath Gieson This final article in the MFA mini‑series focuses on the accounts that hold the highest level of trust within an environment. The previous safeguards address where and how access occurs. This safeguard focuses on who holds the keys. Administrative accounts have the ability to create users, modify security settings, disable controls, and access sensitive systems. When an attacker gains administrative access, the...















