Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› What should organisations do when risk based MFA…
Authentication, Authorisation & Trust

What should organisations do when risk based MFA is not available in their login system?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Authentication, Authorisation & Trust

If risk based MFA is not available, organisations should still require standard MFA registration wherever possible, then layer compensating controls such as stronger password screening, user education, and tighter lockout policies. The goal is to reduce reliance on passwords alone. Risk based prompts are useful, but baseline MFA remains the more important control.

What to do when risk based MFA is unavailable

When a login system cannot make step-up decisions dynamically, the right response is to keep authentication simple but resilient. The baseline objective is still to verify users with stronger MFA, reduce password dependence, and make account recovery and lockout behaviour hard to abuse. Risk-based prompts are helpful, but they are an enhancement, not the core control.

Build the strongest baseline MFA the system will support

If the product cannot risk-score the login, organisations should make standard MFA mandatory for as many users and flows as possible. That means avoiding password-only sign-in for privileged access, remote access, and any system that can reach sensitive data or administrative functions. Where possible, prefer phishing-resistant methods such as passkeys or security keys over SMS or OTP.

Baseline MFA matters because the attack does not stop when the system lacks risk signals. Attackers still try credential stuffing, phishing, MFA fatigue, token theft, and social engineering. In practice, the control question becomes whether the organisation can still force a second factor consistently and whether recovery paths are equally protected. The NIST SP 800-63 Digital Identity Guidelines remain the clearest reference for choosing stronger authenticators and thinking about assurance rather than convenience alone.

For organisations that are replacing legacy login patterns, the most useful internal reference is the Workforce Identity Security Guide, which covers phishing-resistant MFA, recovery, and step-up alternatives that help when risk signals are unavailable.

Compensating controls should shrink the password attack surface

Without risk-based MFA, compensating controls need to do more of the heavy lifting around weak-password and recovery abuse. Strong password screening, blocklists against known compromised passwords, tighter lockout thresholds, alerting on repeated failures, and user education about phishing all become more important. The aim is not to pretend passwords are safe, but to make password abuse less scalable.

This is also where account recovery deserves scrutiny. If recovery is easier than login, the attacker will move to the weaker path. Organisations should make password reset, help desk verification, and MFA reset workflows materially harder to social-engineer than ordinary sign-in. The Passwordless and Passkeys Guide is useful here because it ties stronger authentication to safer recovery design, not just better sign-in UX. For teams choosing a platform, the IAM and Identity Provider Buyer's Guide is a practical way to compare MFA and recovery capabilities rather than accepting a login system's defaults.

Design for the attacks that bypass simple login prompts

Risk-based MFA mainly helps when the system can detect unusual context and react. If that is missing, organisations should assume the adversary will try to bypass the login boundary altogether through session theft, phishing, or abuse of dormant and weakly governed accounts. That makes lockout policy, recovery controls, session expiry, and privileged access hygiene more important than simply adding another OTP option.

Recent breach patterns show why. A dormant account with no MFA, a session token stolen through a proxy attack, or a fatigue attack against a help desk can all defeat a login flow that looks acceptable on paper. The underlying failure is not just weak authentication, but a weak end-to-end access path. Internal case studies such as Colonial Pipeline ransomware attack, CitrixBleed exploitation 2023, and Uber Breach show how attackers move around missing or weakened MFA rather than through it.

Risk and Threat Considerations

When risk-based MFA is unavailable, the main exposure is that every login is treated as equally safe even when it is not. That increases the value of stolen passwords, phishing kits, push fatigue, and account recovery abuse, especially for remote access and admin paths.

Failure mechanism: The organisation relies on a static login decision, so it cannot step up authentication when sign-in conditions look suspicious or when a session has been manipulated.

Impact: Attackers gain a simpler path to account takeover, lateral movement, and unauthorized access to sensitive systems, while defenders lose an important signal for catching abnormal access early.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesAuth assurance and phishing-resistant MFA are central to fallback login design.
Recommendation — Use AAL guidance to select stronger authenticators and protect recovery paths.
CIS Controls v8CIS-5 — Account ManagementCompensating controls here depend on stronger account and login governance.
Recommendation — Enforce account and login controls that reduce password abuse and recovery risk.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe question centers on fallback MFA, password screening, and credential lifecycle protections.
IA-2 — Identification and Authentication (Organizational Users)Baseline MFA for workforce sign-in is the core control when risk-based prompts are absent.
AC-7 — Unsuccessful Logon AttemptsTighter lockout policies directly address the stated compensating controls.
Recommendation — Manage authenticators and credential lifecycle so login does not depend on passwords alone. Require strong user authentication for all interactive access paths. Tune failed-logon limits to slow credential attacks without blocking legitimate recovery.

Practitioner Guidance

What to prioritise: Treat baseline MFA coverage, recovery hardening, and password hygiene as the minimum control set. If a login flow cannot risk-score, do not accept password-only access for privileged users or high-value systems.

What to verify: Check whether MFA is required on all interactive paths, whether help desk resets are stronger than login, and whether lockout and alert thresholds are tuned to stop low-and-slow abuse without creating avoidable denial of service for legitimate users.

Decision rule: If you must choose between adding a weaker login enhancement and enforcing stronger baseline MFA everywhere, choose the latter. The practical control failure is usually inconsistent enforcement, not the absence of a clever prompt.

Practitioner takeaway: Risk-based MFA improves precision, but consistent MFA enforcement and safe recovery are what actually prevent the common account takeover paths when the system cannot adapt in real time.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org