MFA reduces the value of a stolen password, but it does not remove access that should have been revoked in the first place. If the account or VPN entitlement is still active after the employee leaves, the problem is authorisation persistence. Ransomware teams exploit that residual trust.
Why MFA does not eliminate ransomware access paths
MFA is a control on sign-in, not a guarantee that the underlying account is no longer trusted. If a VPN, SSO session, or legacy account remains active after offboarding, an attacker who reaches that path can still inherit valid access. That is why ransomware operators often look for dormant entitlements, stale remote access, and reusable sessions rather than only trying to crack passwords.
When access persists, MFA may still block one login method, but it does not fix the entitlement problem itself. The security question is whether the account should exist at all, whether the privilege is still needed, and whether the session or token can outlive the original sign-in. If those conditions are wrong, the organisation has residual trust even when MFA is enabled.
Phishing-resistant MFA can raise the cost of credential theft, but it does not by itself remove excessive access, stop account reuse, or invalidate long-lived remote access relationships. In practice, ransomware risk often survives because the attacker only needs one path that was never revoked, not a fresh password compromise.
Why authorisation persistence is the real failure mode
The core failure is authorisation persistence: the account, role, or VPN entitlement still works after the person should no longer have access. Workforce Identity Security Guide is useful here because offboarding, recovery paths, and session theft all sit in the same trust chain. If deprovisioning is slow or incomplete, MFA simply protects a stale access path instead of removing it.
That distinction matters because ransomware crews usually do not need full administrative compromise to create impact. A normal user account with shared drives, remote desktop, or VPN access can be enough to stage malware, move laterally, or trigger encryption. The problem is not only how the attacker authenticates, but what that authenticated session is still allowed to do.
Residual trust also shows up in reused credentials, inactive accounts, help-desk resets, and session tokens that remain valid after a password change. MFA Guide covers these bypass patterns well: fatigue, relay, token theft, and legacy authentication all demonstrate that stronger login factors do not automatically equal stronger access governance.
What ransomware operators exploit after MFA is in place
Once MFA exists, attackers tend to shift toward whatever is still trusted by the organisation: stale VPN accounts, forgotten contractors, unrevoked SaaS access, token replay, or compromised help-desk workflows. Colonial Pipeline ransomware attack is a clean example of how a dormant VPN account can become a live entry point when access was never retired.
They also target the places where MFA does not bind well to the full session lifecycle. Session theft, remote-access token replay, and mismanaged recovery flows let an adversary continue operating after the initial authentication event. CitrixBleed exploitation 2023 is a useful reminder that stolen session material can bypass the sign-in step entirely.
For broader identity coverage, Workforce Identity Security Guide and the NIST SP 800-63 Digital Identity Guidelines both point toward the same operational reality: authentication strength matters, but lifecycle, reauthentication, and assurance level are what determine whether access remains trustworthy over time.
Risk and Threat Considerations
MFA can reduce password-based compromise, yet ransomware risk remains when the attack path is entitlement persistence, session theft, or recovery abuse. The practical exposure is that defenders may believe an account is safer than it really is while stale access, legacy auth, or unrevoked remote connectivity still provide a workable intrusion path.
Failure mechanism: An attacker or former insider uses an active but no longer justified account, VPN profile, or session token to enter the environment and reach data or systems that should have been cut off at offboarding or privilege review.
Impact: Ransomware operators can use that residual access to stage tools, spread laterally, and encrypt critical systems even though MFA is present on the login flow.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Covers lifecycle and rotation of authenticators that attackers may abuse after compromise. |
| AC-2 — Account Management | Directly addresses provisioning, disabling, and reviewing accounts that can persist after offboarding. | |
| IA-2 — Identification and Authentication (Organizational Users) | MFA changes authentication strength but not whether access should still exist. | |
| Recommendation — Enforce rotation, revocation, and lifecycle review for authenticators and access paths. Disable unused accounts quickly and review account status continuously. Require strong authentication while separately validating entitlement and account status. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Identity governance is needed to remove stale access, not just protect sign-in. |
| A.5.18 — Access rights | Access rights must be granted, reviewed, and removed to prevent residual trust. | |
| Recommendation — Maintain authoritative identity records and retire access promptly. Review and revoke access rights on exit, role change, and exception expiry. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Residual access is the core failure mode when accounts are not removed on time. |
| NHI-07 — Long-Lived Secrets | Long-lived sessions or secrets can keep access alive beyond the original login. | |
| Recommendation — Revoke credentials and access immediately when the identity is no longer needed. Shorten secret and token lifetimes, and rotate or revoke long-lived credentials. | ||
| CIS Controls v8 | CIS-5 — Account Management | Prescribes managing inactive, temporary, and privileged accounts that drive residual access risk. |
| CIS-6 — Access Control Management | Supports restricting and reviewing remote access and privilege that MFA alone cannot remove. | |
| Recommendation — Remove dormant access paths and validate account ownership and necessity. Limit, review, and revoke access rights based on current business need. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | Zero trust requires continuous validation and least privilege, not a one-time MFA check. |
| Recommendation — Continuously verify access and minimize standing privilege across sessions. | ||
Practitioner Guidance
What to prioritise: Verify that offboarding, contractor exit, and privilege reduction actually remove access, not just passwords. If an account can still reach production through VPN, SSO, or a cached session, treat it as an active attack path until proven otherwise.
What to verify: Check whether remote access, recovery workflows, and dormant accounts are governed by the same lifecycle controls as interactive sign-in. The most common mistake is measuring MFA coverage while ignoring whether the entitlement itself should already have been revoked.
What good looks like: Access disappears quickly when it is no longer needed, session lifetimes are bounded, and recovery paths are tightly controlled. In that state, MFA is one layer in a broader trust model instead of the only thing standing between an attacker and retained access.
Practitioner takeaway: MFA protects authentication events, but ransomware resilience depends on ending trust when access should end, and on making sure sessions, entitlements, and recovery paths cannot outlive the business need.