Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Mfa Rollout

ASecurity

Plan and execute organization-wide MFA adoption — phishing-resistant methods, enrollment, exceptions, and measurement.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentsrustgotestingsecurity

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill mfa-rollout --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Mfa Rollout?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Mfa Rollout
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-mfa-rollout/badge)](https://www.skillsdirectory.com/skills/aicodedecode-mfa-rollout)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: mfa-rollout
description: Plan and execute organization-wide MFA adoption — phishing-resistant methods, enrollment, exceptions, and measurement.
category: security
---

## Overview

Multi-factor authentication is the single most effective control against credential theft: it neutralizes password leaks, phishing (with phishing-resistant methods), and credential stuffing at the login step. Yet rollouts stall on user friction, legacy apps, and exception sprawl. A successful rollout is a change-management project with a technical core.

This skill covers the rollout end to end: method selection, phased enrollment, legacy-app handling, exception governance, and metrics that prove coverage.

MFA rollout is change management disguised as a security project: the technology decisions take weeks, the human adoption takes quarters. Success depends on executive air cover, empathetic support, and relentless measurement. Organizations that treat it as 'turn it on Friday' spend the next year fighting shadow exceptions and helpdesk fires.

## When to use

- Mandating MFA org-wide (or for privileged/remote access first).
- Upgrading from SMS/TOTP to phishing-resistant MFA (FIDO2/passkeys).
- Fixing stalled adoption or runaway exception lists.
- Meeting compliance, cyber-insurance, or customer requirements for MFA.

## Core concepts

- **Not all MFA is equal:** phishing-resistant (FIDO2 security keys, passkeys, Windows Hello for Business, certificate-based) defeats real-time phishing proxies; TOTP is good; SMS and voice are weak (SIM swap, interception) — use only as a fallback, never the standard.
- **Phased rollout:** start with highest risk — admins, IT, finance, executives, remote access — then expand. Big-bang rollouts create support chaos.
- **Enrollment is the project:** the technology is easy; getting 5,000 people enrolled with working recovery methods is the work. Plan comms, helpdesk capacity, and enrollment windows.
- **Recovery must be secure:** account recovery is the attacker's plan B. Define secure recovery (verified identity + admin approval + logging), not "answer your security questions."
- **Legacy apps:** inventory apps that cannot do modern MFA; options are federation via SSO, MFA-gating at the network/VPN layer, compensating controls, or retirement. No silent exemptions.
- **Exceptions with expiry:** break-glass and service accounts get documented exceptions with owners, compensating controls, and review dates — not permanent holes.

- **Number-matching and context.** For push-based MFA, require number matching and show login context (location, app) — it defeats accidental-approve fatigue attacks.
- **Enrollment windows with support.** Staff enrollment helpdesks during each wave's deadline week; most failures cluster at the deadline and are solvable in minutes with help.
- **Adaptive policies.** Combine MFA with risk signals (new device, unusual location) so low-risk logins stay smooth while high-risk ones step up — friction where it counts.

## Practical workflow

1. **Inventory and prioritize:** list all authentication surfaces (SSO apps, VPN, admin consoles, legacy apps, service accounts). Rank by risk: privileged access and internet-facing first.
2. **Choose the standard:** phishing-resistant MFA as the default (passkeys/FIDO2); TOTP as acceptable fallback; SMS/voice deprecated. Document the standard and get leadership sign-off.
3. **Pilot:** 50–200 users across roles, including skeptics. Measure enrollment time, support tickets, and login friction. Fix the rough edges before scale.
4. **Phase the rollout:** waves by risk group with clear deadlines, executive sponsorship, and comms ("why this matters" + how-to). Track enrollment % per wave publicly.
5. **Handle the hard cases:** legacy apps get a migration/federation plan with dates; service accounts get non-interactive controls (managed identities, vaulted creds, IP restrictions); break-glass accounts get sealed, monitored, regularly-tested procedures.
6. **Enforce and measure:** switch from opt-in to enforced (conditional access / policy), close exception loopholes, and report MFA coverage %, method mix, and auth-attack block rates. Celebrate the blocked attacks — it sustains the program.

### Rollout checklist

- [ ] Auth surface inventory complete; risk-ranked waves defined
- [ ] MFA standard documented (phishing-resistant default)
- [ ] Pilot completed; support playbook ready
- [ ] Comms plan + executive sponsor per wave
- [ ] Secure recovery procedure defined, tested, and logged
- [ ] Legacy-app plan with dates (federate, gate, or retire)
- [ ] Exceptions documented with owners, controls, expiry
- [ ] Enforcement enabled; coverage dashboard live

### Sustaining the practice

- Report coverage and blocked-attack stats monthly to sustain sponsorship
- Review exceptions quarterly; every exception needs progress toward closure
- Track method upgrades (SMS to authenticator to FIDO2) as a maturity ladder
- Include MFA in onboarding so new hires start enrolled

### Metrics that prove it works

- Enrollment % per wave vs deadline
- Helpdesk ticket volume per 100 enrollments (friction indicator)
- Authentication failure rate during rollout (watch for lockouts)
- Method mix: % on phishing-resistant vs TOTP vs SMS

## Common pitfalls

- **SMS as the standard.** It is better than nothing but vulnerable to SIM swap and interception. Do not standardize on the weakest method.
- **Permanent exceptions.** Every exception needs an owner, compensating controls, and an expiry — review quarterly.
- **Ignoring recovery.** Attackers target helpdesk recovery flows. An unsecured recovery path bypasses your entire MFA investment.
- **Big-bang rollout.** Support drowns, users revolt, leadership blinks. Phase it.
- **Service accounts forgotten.** Non-human accounts with static passwords and no MFA are prime targets. Inventory and vault them.
- **Declaring victory at 90%.** The last 10% is usually admins, legacy systems, and exceptions — i.e., the highest risk. Finish the job.
- **Enforcing before support is ready.** Flipping the enforcement switch with an unprepared helpdesk creates a outage of trust. Pilot, staff up, then enforce.
- **Never testing break-glass.** Sealed emergency accounts with untested procedures fail during the actual emergency. Test recovery annually.
- **Allowing 'temporarily' weaker methods indefinitely.** Temporary SMS fallbacks become permanent without expiry dates and enforcement. Time-box everything.
- **Ignoring the user experience of recovery.** A recovery flow that takes three days teaches users to avoid the secure path. Make secure recovery fast and humane.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →