MFA does not guarantee complete security: attacks target enrollment, recovery, and session
Multi-Factor Authentication (MFA) only covers a fraction of the lifecycle of a digital identity, leaving the enrollment, recovery, and session management phases vulnerable. Attackers are exploiting these gaps with increasingly sophisticated techniques, as demonstrated by the CISA/FBI AA23-320A advisory updated in July 2025.
Quick Answer
MFA alone does not guarantee complete security for a digital identity. The main vulnerabilities concern:
- Insufficient verification of the real identity
- Insufficient control of authenticators
- Post-login behavior not monitored
The three emerging criticalities in the use of MFA
The main vulnerabilities identified concern: insufficient verification of the real identity associated with the account, insufficient control of the required authenticators, and the absence of monitoring of post-login behavior.
The NIST Digital Identity Guidelines and the multidimensional approach
The NIST Digital Identity Guidelines (SP 800-63) abandoned the single Level of Assurance model as early as the 2017 revision 3. Revision 4, published in July 2025, introduces an orthogonal approach with three dimensions: IAL (Identity Assurance Level), AAL (Authenticator Assurance Level), and FAL (Federation Assurance Level).
The orthogonality of assurance levels and its implications
The orthogonality of assurance levels has practical consequences often overlooked. A system can operate with AAL3 (hardware authenticator resistant to phishing) and IAL1 (unverified identity), a technically valid but insecure configuration. Revision 4 also introduces continuous evaluation metrics, treating assurance as a magnitude to be reassessed over time.
The new attack techniques that bypass MFA
More sophisticated attackers have stopped trying to bypass the authenticator and instead seek to obtain one. The CISA/FBI AA23-320A advisory documents cases where aggressors pose as employees at the help desk to obtain credential resets and transfer MFA to a device under their control.
The importance of the FAL level and federation attacks
In some campaigns, attackers have added a federated identity provider to the victim's SSO tenant with automatic account linking (T1484.002), gaining the ability to authenticate as any user. This is an attack that operates entirely at the FAL level and that no AAL control is able to intercept.
The vulnerabilities of the recovery process
A study by Kunke, Wiefling, Ullmann, and Lo Iacono tested twelve account recovery strategies for passwordless FIDO2 authentication, finding none fully satisfactory. Over 60% of respondents consider account recovery as the most serious gap in FIDO2 integration.
Organizational and architectural countermeasures
To mitigate these vulnerabilities, it is essential to adopt organizational and architectural measures. The reset must be linked to a new identity verification that does not rely on knowledge factors. For privileged accounts, it is advisable to perform documentary verification with liveness detection or recognition on a pre-registered video channel.
Best practices for authenticator management
It is advisable to allow the registration of new authenticators only from managed and compliant endpoints, blocking registrations from anomalous ASN or geolocations. New authenticators must be activated in a deferred manner, with notifications on already registered channels, so that the legitimate owner has a useful time window to refuse.
The importance of privilege separation
From an organizational perspective, those who perform a reset should not be able to elevate their own privileges. Administrative tiers require dual approval, and verification scripts should not be bypassable by invoking urgency.
The impact of NIS2, DORA, and eIDAS 2.0 regulations
The NIS2, DORA, and eIDAS 2.0 regulations require specific compliance requirements in terms of digital identity management. In particular, the DORA regulation, applicable from January 2025, imposes rigorous criteria for digital operational resilience for critical infrastructures.
The importance of cyber insurance for risk management
Given the complexity of threats, it is fundamental to evaluate the implementation of an adequate cyber risk policy. Proactive risk management with an MDR service can help identify and mitigate these vulnerabilities promptly.
Integration with Identity Access Management systems
Integration with advanced Identity Access Management (IAM) systems can significantly improve the management of digital identities. These systems allow the implementation of granular controls and continuous monitoring of user behavior.
The importance of continuous evaluation
Revision 4 of the NIST Digital Identity Guidelines introduces the concept of continuous evaluation, treating assurance as a magnitude to be reassessed over time. This approach is fundamental to adapting to the evolution of threats and ensuring an adequate level of security in the long term.
The implications for compliance with regulations
Organizations must ensure that their digital identity management processes are compliant with current regulations, including NIS2, DORA, and eIDAS 2.0. This requires a structured and documented approach, with periodic checks and external audits.
The importance of user training
User training is a crucial element for the security of digital identities. Users must be aware of the risks associated with social engineering techniques and the correct procedures for authenticator management and account recovery.
The evolution of the IAM solutions market
The global Identity Access Management (IAM) market is expected to grow by 14% annually until 2028, with an accelerated transition to cloud-native solutions. The most advanced platforms now integrate machine learning for anomalous behavior and continuous evaluation APIs, reducing false positives by 30% in traditional systems. Microsoft Entra Verified ID and Okta Identity Engine represent the most relevant use cases for the practical implementation of the NIST SP 800-63B-4 guidelines.
The economic impact of attacks on identity providers
An analysis conducted by Accenture in 2025 estimates that attacks on identity providers cost European organizations between €2.3 and €3.7 million annually, considering only the direct costs of breach remediation. The average cost of an incident involving federated systems has increased by 42% compared to 2023, with peaks of 78% in the financial sector. This makes the adoption of specialized SOC as a Service solutions crucial.
The differences between sectors in MFA management
Sectors with more stringent regulatory requirements, such as banking and insurance, show a higher adoption of hardware authenticators (AAL3) for privileged accounts, while SMEs tend to maintain OTP-based solutions. A Gartner study highlights that 68% of large companies have implemented continuous biometric verifications for remote users, compared to 23% of companies with fewer than 500 employees.
The role of ISO 27001 standards in identity management
The latest revision of the ISO/IEC 27001:2022 standard includes specific provisions for the management of digital identities, with particular attention to the lifecycle of authenticators. Control A.9.4.2 now requires documented processes for the revocation and transfer of authenticators, with mandatory quarterly audits for accounts with elevated privileges. This aligns the standard with the continuous evaluation needs introduced by the NIST.
The challenges in managing mobile authenticators
Smartphone-based authenticators present unique vulnerabilities, as demonstrated by CVE-2024-37000, which affected Google Authenticator, allowing session cloning. The most recent solutions, such as Microsoft Authenticator with phone number, introduce an additional verification level via SMS one-time password, reducing the risk of account takeover. However, 35% of users disable this functionality for convenience.
The impact of MiCA regulation on digital identities
The MiCA regulation, applicable from January 2025, introduces specific requirements for user identification in crypto services. Exchange platforms must now implement identity verifications (IAL2) for transactions exceeding €1,000, with data retention for at least 5 years. This sets a precedent for the adoption of similar standards in other sectors at high risk of fraud.
The differences between NIS2 and DORA in identity management
While NIS2 focuses on general operational resilience, DORA imposes stricter requirements for the management of privileged user identities in the financial sector. In particular, DORA requires that identity providers used by financial institutions be ISO 27001 certified with specific controls for authenticator management. This creates a regulatory gap that organizations must bridge by 2026.
The adoption of zero trust in response to new threats
The adoption of zero trust architectures has increased by 22% in 2025, with a particular focus on the protection of digital identities. The most advanced solutions, such as Zscaler Private Access, integrate now session behavior analytics to detect suspicious post-login activities. However, only 15% of organizations have implemented zero trust controls for account recovery, representing a critical area for improvement.
The tax implications for companies adopting crypto solutions
The adoption of institutional crypto custody solutions for authenticator management requires a review of crypto tax Italy strategies. Companies must consider the tax impact of transactions related to digital identity management, with particular attention to the traceability requirements imposed by the MiCA regulation. A specialized crypto accountant can help navigate these complexities.
The future prospects for digital identity management
Emerging trends indicate an increase in the adoption of continuous biometric solutions for session management, with a particular focus on privacy. Facial recognition technologies with liveness detection are evolving rapidly, with false positive errors reduced to 0.1%. However, concerns related to user privacy and GDPR compliance remain a significant obstacle to large-scale adoption.
The importance of continuous training for security professionals
The increasing complexity of threats requires continuous investment in the training of security professionals. Advanced certification programs, such as the Certified Identity and Access Manager (CIAM), are gaining popularity among CISOs. These programs cover the latest attack techniques and best practices for digital identity management, with a particular focus on NIS2 and DORA regulations.
The opportunities for identity governance solution providers
The identity governance solutions market is rapidly expanding, with a 28% increase in implementations in 2025. The most advanced platforms, such as SailPoint and One Identity, are integrating continuous evaluation and machine learning functionalities for the detection of anomalous behaviors. This creates new opportunities for providers of specialized managed Security Operations Center solutions.
The challenges in managing identities in hybrid environments
Managing identities in hybrid environments presents unique challenges, with 42% of organizations reporting difficulties in synchronizing authenticators between cloud and on-premise. The most recent solutions, such as Azure AD Connect, offer advanced synchronization and continuous evaluation functionalities, but require careful configuration to ensure security. Organizations must carefully evaluate the risks associated with managing identities in distributed environments.
The impact of digital transformation on identity management
Digital transformation has accelerated the need for advanced solutions for digital identity management. Organizations must adopt a proactive approach to security, integrating Managed Detection and Response and Security Information and Event Management solutions to continuously monitor activities related to identities. This requires a significant investment in data analysis capabilities and staff training.
The prospects for the future of identity management
The future of digital identity management is characterized by greater integration of advanced technologies such as artificial intelligence and machine learning. Future solutions will need to be able to quickly adapt to the evolution of threats, with a particular focus on compliance with emerging regulations. Organizations that invest today in advanced identity governance solutions will be better prepared to face tomorrow's challenges.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.