Cyber Essentials question · User access control
Is multi-factor authentication (MFA) enabled on EVERY user account that supports it — including all cloud services and email, for every user, not just admins?
This is a mandatory item. Answering “No” fails the whole User access control section — and the overall assessment — however strong everything else is.
Why assessors ask this
Under the current question set, MFA missing on ANY in-scope account fails the whole User Access Control section. Passkeys / FIDO2 count.
Priority fix
Priority: enable MFA on every in-scope account — missing MFA on even one account fails the entire User Access Control section.
What “good” looks like for User access control
- Turn on MFA for every account that supports it — email and cloud services first.
- Give each person their own login; remove shared accounts.
- Use separate admin accounts and a leaver checklist that revokes access on day one.
See where you stand in 5 minutes
Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.
Start the free readiness check →Part of the User access control control.
This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.