Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

NYDFS MFA enforcement: are regulated firms ready for November 1?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: New York’s NYDFS Cybersecurity Regulation now requires MFA across privileged accounts, remote access, and access to nonpublic information by November 1, 2025, with penalties and increased oversight for missed compliance, according to Unixi. The real test is whether regulated firms can prove enforcement across legacy, SaaS, and third-party access without creating usable exceptions.

NHIMG editorial — based on content published by Unixi: The New York DFS Mandate: A Deadline That Can’t Be Missed

By the numbers:

  • By November 1, 2025, all regulated entities must have MFA enforced across privileged accounts, remote access into systems, and any access to nonpublic information.

Questions worth separating out

Q: How should security teams add MFA to legacy apps without changing the origin?

A: Place the authentication decision at the front door, such as CloudFront or another reverse proxy layer, and preserve only the minimum state needed to complete the login flow.

Q: Why do legacy systems make NYDFS MFA compliance harder?

A: Legacy systems often sit outside modern identity flows, so MFA must be layered on through proxies, wrappers, or other compensating controls.

Q: What breaks when MFA is enforced for employees but not vendors or administrators?

A: The organisation ends up with inconsistent assurance, where the most powerful access paths are the least standardized.

Practitioner guidance

  • Map every MFA enforcement gap Inventory privileged accounts, remote access paths, nonpublic information access, contractor pathways, and browser-based applications to identify where MFA is not consistently enforced.
  • Unify privileged and third-party access policy Apply the same MFA enforcement standard to internal administrators, contractors, and vendors, even when their onboarding or monitoring workflow differs.
  • Build audit-ready MFA evidence Create reporting that shows which accounts, applications, and access paths are covered, when exceptions were approved, and when they were removed.

What's in the full article

Unixi's full article covers the operational detail this post intentionally leaves for the source:

  • Specific ways Unixi applies MFA to browser-based applications that do not support native integrations.
  • Operational examples for privileged account protection and third-party access enforcement in regulated environments.
  • Audit dashboard outputs that can help demonstrate MFA coverage during NYDFS examinations.
  • Contextual authentication signals used to balance enforcement with user friction.

👉 Read Unixi's analysis of the NYDFS MFA mandate and compliance deadline →

NYDFS MFA enforcement: are regulated firms ready for November 1?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

NYDFS MFA compliance is really an access-path governance problem. The regulation is explicit about where MFA must apply, but most firms struggle because their environment contains multiple entry paths with different control capabilities. Legacy systems, SaaS applications, and vendor access are where coverage usually fragments. Practitioners should treat this as a control-mapping exercise, not a checkbox exercise.

A few things that frame the scale:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who is accountable if a firm misses the NYDFS MFA deadline?

A: Accountability sits with the regulated entity, not with the application vendor or the identity provider. If coverage is incomplete, the firm must answer for the control gap, the exception handling, and the evidence it can produce during examination.

👉 Read our full editorial: NYDFS MFA mandate turns access control into an audit test



   
ReplyQuote
Share: