Rolling out multi-factor authentication for administrators
Administrative MFA reduces the value of a stolen password only when enrolment, fallback and recovery cannot be used as easier routes into the same privileged account.
Inventory privileged identities
List named administrators, emergency access, automation and supplier accounts across the identity provider and local applications. Remove dormant access and separate human sessions from service credentials before applying a common policy.
Choose factors by threat
Prefer FIDO2 security keys or platform authenticators for high-value roles, with TOTP where required by device coverage. Avoid SMS as the primary administrative control when stronger supported factors are available.
Stage enrolment with proof
Require recent primary authentication, record the enrolled authenticator and provide a confirmation through an independent channel. Pilot with support and platform teams before enforcing by role and application.
Design recovery before enforcement
Issue one-time recovery codes securely, define identity verification for replacement factors and protect emergency accounts with separate custody and alerting. A helpdesk should not disable MFA based on information available in an inbox.
Monitor and review
Alert on factor enrolment, recovery, repeated denial and impossible changes in location. Test loss of an authenticator and identity-provider outage, and review excluded applications until local passwords are removed or controlled.
Do not declare the rollout complete while legacy administration paths accept the same account with password-only authentication.