Organisations should use attack history, user sensitivity, and observed behaviour to decide where stepped-up authentication makes sense. High-risk users, frequent clickers, and people repeatedly targeted by phishing or business email compromise should receive stronger controls first. That lets teams align identity protections with real exposure, rather than applying the same access policy everywhere and hoping it covers the highest-risk users.
How organisations choose where step-up authentication should apply
Good step-up design starts with risk segmentation, not blanket enforcement. Organisations decide by looking at who is most exposed to compromise, which accounts can cause the most damage if abused, and which behaviours suggest a higher likelihood of account takeover. That usually means combining user role, sensitivity of access, recent attack history, and the quality of the sign-in signal.
Attack history is especially useful because it shows where adversaries are already concentrating effort. Repeated phishing, credential stuffing, MFA fatigue, or suspicious login attempts are strong signals that a user or group merits stronger controls earlier than the rest of the population. Teams should also distinguish between ordinary users and high-impact accounts such as administrators, finance approvers, support staff, and anyone with access to sensitive systems or data.
The decision should not be based on a single attribute in isolation. A person with moderate privilege but frequent risky behaviour may deserve stronger challenge than a highly privileged user with low observed exposure. That is why many programmes combine identity risk, access criticality, and context such as device health, location, or impossible travel into one stepped-up access policy. For broader identity programmes, a useful complement is IAM and IGA Basics, which covers how access governance and entitlement review support these decisions.
Which signals matter most in practice
The most reliable inputs are the ones that reflect actual exposure, not just organisational hierarchy. High-risk users, users who have recently triggered security alerts, and people who routinely click suspicious links are all good candidates for stronger authentication. So are users whose roles make them attractive targets, such as executives, payroll, procurement, help desk, and IT admins.
Observed behaviour matters because it reveals whether the normal control set is enough. If a user repeatedly falls for phishing, uses weak recovery paths, or logs in from unusual devices and networks, the organisation should treat that as evidence of increased compromise likelihood. This is where step-up authentication becomes a risk control rather than a ceremonial extra prompt. The MFA Guide is useful for understanding which authentication methods are actually resistant to the attacks that drive these decisions.
Identity teams should also watch for access patterns that expand blast radius. A user who can approve payments, reset credentials, access customer records, or administer infrastructure creates more downside if compromised than someone with low-impact access. In those cases, tighter access controls are not just about sign-in friction, they are about reducing what an attacker can do after the first successful login. Authorisation Models Guide helps separate authentication decisions from entitlement decisions so stronger login policy does not become a substitute for least privilege.
How to turn the policy into a usable control
Organisations usually get the best results by defining risk tiers and mapping each tier to a different level of authentication and access restraint. The practical goal is to reserve the strongest controls for the users and scenarios most likely to suffer account takeover or cause material loss. That makes the policy defensible, explainable, and easier to tune when false positives appear.
A second useful pattern is to treat step-up as conditional, not permanent. If the user is on a trusted device, using a known network, and performing a low-risk action, the system can stay quiet. If the user is accessing a sensitive workflow, acting from a new device, or showing a risky behavioural pattern, step-up can trigger automatically. For sign-in methods that reduce phishing and replay risk, NIST SP 800-63 Digital Identity Guidelines provides the clearest external anchor for assurance levels and stronger authenticators.
Teams should also keep access controls aligned with the same risk tiering. If a group is riskier enough to warrant step-up, it often also deserves narrower privilege, shorter sessions, tighter recovery paths, or more frequent review of its entitlements. Where programme maturity is still uneven, IAM and Identity Provider Buyer’s Guide is a useful reference for capabilities such as phishing-resistant MFA, lifecycle handling, and access policy enforcement.
Risk and Threat Considerations
Step-up authentication becomes ineffective when organisations apply it too broadly or in the wrong places. If high-risk users are not prioritised, attackers can still reach the accounts that matter most, and if low-risk users are overburdened, the control loses credibility and gets bypassed through exceptions or poor recovery paths.
Failure mechanism: Weak segmentation, poor signal quality, or overreliance on static attributes causes the strongest controls to miss the accounts most likely to be targeted, while leaving high-value access with insufficient friction.
Impact: The organisation preserves attacker opportunity, increases the chance of account takeover, and may add friction without materially improving resilience.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Step-up authentication depends on assurance levels and stronger authenticators. |
| Recommendation — Use higher assurance authenticators for users and actions with greater risk. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Workforce step-up decisions depend on how organisational users are authenticated. |
| AC-6 — Least Privilege | Tighter access controls complement step-up by limiting what risky accounts can do. | |
| Recommendation — Apply stronger authentication to organizational users with higher exposure or privilege. Reduce the privileges of accounts that warrant stronger authentication. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access Control | Access control policy must define who gets tighter controls and why. |
| Recommendation — Define risk-based access rules for high-exposure users and systems. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Risk-tiered authentication and access restrictions are core access management work. |
| Recommendation — Prioritise stronger access controls for accounts with greater attack exposure. | ||
Practitioner Guidance
What to prioritise: Start with the accounts whose compromise would cause the largest operational or financial loss, then layer in users with repeated risky behaviour or a proven attack pattern against them. That sequence gives you the fastest reduction in exposure.
What to verify: Make sure the control is driven by observable evidence, such as target status, privilege level, login anomalies, or attack history, rather than job title alone. If you cannot explain why a user is in the stronger tier, the policy is probably too blunt.
Decision rule: If a user is both valuable to an attacker and exposed to recurrent attack pressure, give them stronger authentication first, then narrow their access where possible. If the account can be reset, approved, or delegated into other systems, treat it as high impact even if the user is not a formal administrator.
Practitioner takeaway: The best stepped-up access policy is risk-based and behaviour-aware, because it protects the users most likely to be attacked and the accounts most dangerous to lose.
Related resources from NHI Mgmt Group
- When should organizations review access controls?
- How can organisations tell whether their identity controls are keeping up with machine-speed access?
- How should organisations decide between VPNs and application-level access controls?
- How do organisations know whether privileged access controls are keeping up with AI-driven change?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org