Plan and execute organization-wide MFA adoption — phishing-resistant methods, enrollment, exceptions, and measurement.
Scanned 9/29/2026
npx -y skills add aicodedecode/awesome-muse-skills --skill mfa-rollout --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Mfa Rollout?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/aicodedecode-mfa-rollout)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: mfa-rollout
description: Plan and execute organization-wide MFA adoption — phishing-resistant methods, enrollment, exceptions, and measurement.
category: security
---
## Overview
Multi-factor authentication is the single most effective control against credential theft: it neutralizes password leaks, phishing (with phishing-resistant methods), and credential stuffing at the login step. Yet rollouts stall on user friction, legacy apps, and exception sprawl. A successful rollout is a change-management project with a technical core.
This skill covers the rollout end to end: method selection, phased enrollment, legacy-app handling, exception governance, and metrics that prove coverage.
MFA rollout is change management disguised as a security project: the technology decisions take weeks, the human adoption takes quarters. Success depends on executive air cover, empathetic support, and relentless measurement. Organizations that treat it as 'turn it on Friday' spend the next year fighting shadow exceptions and helpdesk fires.
## When to use
- Mandating MFA org-wide (or for privileged/remote access first).
- Upgrading from SMS/TOTP to phishing-resistant MFA (FIDO2/passkeys).
- Fixing stalled adoption or runaway exception lists.
- Meeting compliance, cyber-insurance, or customer requirements for MFA.
## Core concepts
- **Not all MFA is equal:** phishing-resistant (FIDO2 security keys, passkeys, Windows Hello for Business, certificate-based) defeats real-time phishing proxies; TOTP is good; SMS and voice are weak (SIM swap, interception) — use only as a fallback, never the standard.
- **Phased rollout:** start with highest risk — admins, IT, finance, executives, remote access — then expand. Big-bang rollouts create support chaos.
- **Enrollment is the project:** the technology is easy; getting 5,000 people enrolled with working recovery methods is the work. Plan comms, helpdesk capacity, and enrollment windows.
- **Recovery must be secure:** account recovery is the attacker's plan B. Define secure recovery (verified identity + admin approval + logging), not "answer your security questions."
- **Legacy apps:** inventory apps that cannot do modern MFA; options are federation via SSO, MFA-gating at the network/VPN layer, compensating controls, or retirement. No silent exemptions.
- **Exceptions with expiry:** break-glass and service accounts get documented exceptions with owners, compensating controls, and review dates — not permanent holes.
- **Number-matching and context.** For push-based MFA, require number matching and show login context (location, app) — it defeats accidental-approve fatigue attacks.
- **Enrollment windows with support.** Staff enrollment helpdesks during each wave's deadline week; most failures cluster at the deadline and are solvable in minutes with help.
- **Adaptive policies.** Combine MFA with risk signals (new device, unusual location) so low-risk logins stay smooth while high-risk ones step up — friction where it counts.
## Practical workflow
1. **Inventory and prioritize:** list all authentication surfaces (SSO apps, VPN, admin consoles, legacy apps, service accounts). Rank by risk: privileged access and internet-facing first.
2. **Choose the standard:** phishing-resistant MFA as the default (passkeys/FIDO2); TOTP as acceptable fallback; SMS/voice deprecated. Document the standard and get leadership sign-off.
3. **Pilot:** 50–200 users across roles, including skeptics. Measure enrollment time, support tickets, and login friction. Fix the rough edges before scale.
4. **Phase the rollout:** waves by risk group with clear deadlines, executive sponsorship, and comms ("why this matters" + how-to). Track enrollment % per wave publicly.
5. **Handle the hard cases:** legacy apps get a migration/federation plan with dates; service accounts get non-interactive controls (managed identities, vaulted creds, IP restrictions); break-glass accounts get sealed, monitored, regularly-tested procedures.
6. **Enforce and measure:** switch from opt-in to enforced (conditional access / policy), close exception loopholes, and report MFA coverage %, method mix, and auth-attack block rates. Celebrate the blocked attacks — it sustains the program.
### Rollout checklist
- [ ] Auth surface inventory complete; risk-ranked waves defined
- [ ] MFA standard documented (phishing-resistant default)
- [ ] Pilot completed; support playbook ready
- [ ] Comms plan + executive sponsor per wave
- [ ] Secure recovery procedure defined, tested, and logged
- [ ] Legacy-app plan with dates (federate, gate, or retire)
- [ ] Exceptions documented with owners, controls, expiry
- [ ] Enforcement enabled; coverage dashboard live
### Sustaining the practice
- Report coverage and blocked-attack stats monthly to sustain sponsorship
- Review exceptions quarterly; every exception needs progress toward closure
- Track method upgrades (SMS to authenticator to FIDO2) as a maturity ladder
- Include MFA in onboarding so new hires start enrolled
### Metrics that prove it works
- Enrollment % per wave vs deadline
- Helpdesk ticket volume per 100 enrollments (friction indicator)
- Authentication failure rate during rollout (watch for lockouts)
- Method mix: % on phishing-resistant vs TOTP vs SMS
## Common pitfalls
- **SMS as the standard.** It is better than nothing but vulnerable to SIM swap and interception. Do not standardize on the weakest method.
- **Permanent exceptions.** Every exception needs an owner, compensating controls, and an expiry — review quarterly.
- **Ignoring recovery.** Attackers target helpdesk recovery flows. An unsecured recovery path bypasses your entire MFA investment.
- **Big-bang rollout.** Support drowns, users revolt, leadership blinks. Phase it.
- **Service accounts forgotten.** Non-human accounts with static passwords and no MFA are prime targets. Inventory and vault them.
- **Declaring victory at 90%.** The last 10% is usually admins, legacy systems, and exceptions — i.e., the highest risk. Finish the job.
- **Enforcing before support is ready.** Flipping the enforcement switch with an unprepared helpdesk creates a outage of trust. Pilot, staff up, then enforce.
- **Never testing break-glass.** Sealed emergency accounts with untested procedures fail during the actual emergency. Test recovery annually.
- **Allowing 'temporarily' weaker methods indefinitely.** Temporary SMS fallbacks become permanent without expiry dates and enforcement. Time-box everything.
- **Ignoring the user experience of recovery.** A recovery flow that takes three days teaches users to avoid the secure path. Make secure recovery fast and humane.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!