SourceSecurity.com
  • Products
    CCTV
    • CCTV cameras
    • CCTV software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network video recorders (NVRs)
    • IP Dome cameras
    • CCTV camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Audio, video or keypad entry
    • Electronic locking devices
    • Access control cards/ tags/ fobs
    • Access control system accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    One system, one card
    One system, one card
    Hikvision AOV 4G Solar Camera Series for Off-Grid Video Security

    Hikvision AOV 4G Solar Camera Series for Off-Grid Video Security

    KentixONE – IoT Access and Monitoring For Data Centres

    KentixONE – IoT Access and Monitoring For Data Centres

    Climax Technology HSGW-Gen3 Modular Smart Security Gateway

    Climax Technology HSGW-Gen3 Modular Smart Security Gateway

    Delta Scientific DSC50 ‘S’ Barrier: Portable, Crash-Rated Vehicle Mitigation Solution

    Delta Scientific DSC50 ‘S’ Barrier: Portable, Crash-Rated Vehicle Mitigation Solution

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    One system, one card
    One system, one card
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Alcatraz achieves SOC 2 for biometric security
    • Datalogic AI tech drives retail innovation at NRF 2026
    • Deep Sentinel launches Mobile Monitoring Trailer
    • Eplan and CADENAS partnership enhances data access
    One system, one card
    One system, one card
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • Why open matters in the age of AI
    • What are emerging applications for physical security in transportation?
    • What is the most overlooked factor when installing security systems?
    • Amid rising certificate demands, stricter compliance and quantum threats, PKIaaS is a necessity
    One system, one card
    One system, one card
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    One system, one card
    One system, one card
    Alamo enhances security with Alcatel-Lucent solutions

    Alamo enhances security with Alcatel-Lucent solutions

    The University of Dundee implements HID for modern access control

    The University of Dundee implements HID for modern access control

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    SBB upgrades surveillance with Hanwha Vision cameras

    SBB upgrades surveillance with Hanwha Vision cameras

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    One system, one card
    One system, one card
    Intersec Dubai 2026

    Intersec Dubai 2026

    DIMDEX 2026

    DIMDEX 2026

    DISTRIBUTECH International 2026

    DISTRIBUTECH International 2026

    Munich Security Conference (MSC) 2026

    Munich Security Conference (MSC) 2026

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Eagle Eye Networks
    • Hanwha Vision America
    Other Resources
    • eMagazines
    • Videos
    One system, one card

    One system, one card

    Aligning physical and cyber defence for total protection

    Aligning physical and cyber defence for total protection

    Understanding AI-powered video analytics

    Understanding AI-powered video analytics

    Modernizing access control

    Modernizing access control

About us Advertise
  • Wire-free locks
  • AI special report
  • Cyber security special report
  • Casino security & surveillance
  • 6
Video analytics
  • Home
  • About
  • White papers
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • Videos

Check out our special report on casino security

Get it now!

Boost MFA security: Tips for managed service providers

1 Mar 2023

Boost MFA security: Tips for managed service providers
Contact company
Contact SaaS Alerts
icon Add as a preferred source Download PDF version

It wasn’t too long ago that multi-factor authentication (MFA) was considered the Holy Grail of cybersecurity. More than a few vendors and analysts predicted that MFA would eventually prevent 99 percent of cyber attacks. But here they are. MFA is a standard security tool used by most businesses (and consumers), yet breaches are still happening.

So, what happened? Where did MFA go wrong? And how can managed service providers (MSPs) get the most out of MFA solutions for their clients?

Critical business information

The MFA concept was developed decades ago, but really burst onto the scene 10 years ago when enterprise data started to move out of the data center to third-party Software as a Service (SaaS) platforms. With users’ judgement and their ability to keep their credentials to themselves the only thing between malicious actors and their critical business information, it became clear that usernames and passwords were simply not robust enough anymore.

MFA provided a way to ensure users were who they said they were by requiring two points of authentication

MFA provided a way to ensure users were who they said they were by requiring two points of authentication: the user and a device. The thinking is that it is unlikely that a malicious actor would be able to compromise two separate vector points. They may have a password, but not access to a known device—essentially making it statistically difficult for a bad actor to gain access to an endpoint, network or cloud-based SaaS platform.

Most security solutions

However, like most security solutions, MFA only works if it is used 100 percent of the time and is being used appropriately. Unfortunately, MFA can be disruptive to workflows (having to authenticate every time you log in can be tedious), and users found multiple work-arounds to maintain productivity.

A popular workaround that continues to be used today is sharing authentication. One egregious example is when an engineering team leverages an iPad on a stool in the middle of the office that everyone uses to authenticate. If users think about it, this is ludicrous. There’s no such thing as a shared identity, and it undermines everything that MFA was intended to resolve.

Second authentication method

This would completely mitigate the reason users have a security camera in the first place

Imagine if a home security system relied exclusively on a keypad at the front door to let people in. Yes, users can prevent people without the code from entering home, but users really have no idea who is walking around the living room. 

Adding a second authentication method, such as a camera, allows users to make sure the person entering has the right credentials (the code) and is who they say they are. Users would never turn off the camera for ease of access purposes. This would completely mitigate the reason users have a security camera in the first place.

Standard industry insiders

Yet, MFA is rife with under- and misuse—effectively abolishing the protection it is supposed to provide. Couple this with new, sophisticated hacking techniques that malicious actors have developed through the years, and it’s clear that MFA is not living up to the standard industry insiders thought possible 10 years ago.

MSPs have an opportunity and an obligation to help their customers fix their MFA troubles. After all, it’s in users best interest to make sure the clients are as secure as possible. Not only does it help elevate the level of service they are providing, breaches are time consuming and expensive to remediate, lowering the margins considerably. Thankfully, there are a few things that MSPs can do to boost the effectiveness of MFA solutions for their clients.

Implement MFA code timeouts

Hackers would have to act immediately—within seconds in some cases—to gain access

A common hacking technique is to bombard users with MFA login requests to point where MFA fatigue sets in and, in a lapse of judgement, the user enters an MFA code into a false web form. Code in hand, the malicious actor can log in and authenticate without a device or app. 

MSPs can prevent MFA fatigue by implementing code timeouts that cause MFA credentials to expire after 30 seconds, one minute or two minutes depending on policies set by an administrator. This doesn’t completely eliminate MFA fatigue as a technique, but it shortens the strike opportunity dramatically. Hackers would have to act immediately—within seconds in some cases—to gain access, which is very difficult and highly unlikely.

Encourage the use of authenticator apps

Another common hacking technique is a man-in-the-middle (MitM) attack where malicious actors redirect MFA codes to their own device rather than the user’s device.

This only works when codes are sent via SMS or text message because the device in the user’s possession is not generating the code. However, a third-party authenticator app generates the MFA code directly on the user’s device, making it impossible to redirect the code to another device. Google and Okta are examples of these third-party authenticator apps that users can mandate to their clients.

Achieve complete visibility and control over MFA activity

MSPs can do this by closely monitoring SaaS platforms and other web applications

Ensuring compliance requires complete visibility and control over MFA activity as well as the ability to trigger actions that stop the attack or mitigate the damage. 

MSPs can do this by closely monitoring SaaS platforms and other web applications for suspicious login behavior while maintaining the ability to lock out suspicious users, block data exfiltration or trigger another authentication process. MSPs need to do this perpetually (24 hours a day, 365 days a year), in real time and at scale.

Another authentication process

MFA hasn’t lived up to its lofty expectations, but it is still a powerful security tool for keeping data, applications and users safe from unauthorised logins.

MSPs have a responsibility to improve the effectiveness of their clients’ MFA solutions while also providing a value-added service. It all comes down to visibility and control over MFA activity. Adding monitoring capabilities from SaaS Alerts can proactively identify and automatically lock out suspicious login behaviour and force reauthorisation.

From facial recognition to LiDAR, explore the innovations redefining gaming surveillance

Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Network / IP
  • Security devices
  • Security cameras
  • Security camera systems
  • Radio frequency Identification
  • Video analytics
  • Network cameras
  • Physical Security Information Management (PSIM)
  • Network Video Recorders
  • Related links
  • ANPR Software CCTV software
  • Access Control Software Access control software
  • Card Access control software
  • Detection Software CCTV software
  • Mifare Access control software
  • Drawing Software CCTV software
  • Proximity Access control software
  • IP Surveillance Software CCTV software
  • Central Monitoring Option Access control software
  • Recording Software CCTV software
  • Surveillance Software CCTV software
  • Management Systems Upgrade Access control software
  • Server software for MSDE Access control software
  • Related categories
  • CCTV software
  • Access control software
Related white papers
Understanding AI-powered video analytics

Understanding AI-powered video analytics

Download
Open credential standards and the impact on physical access control

Open credential standards and the impact on physical access control

Download
What is a universal RFID reader?

What is a universal RFID reader?

Download
Related articles
Transforming video data: Videonetics 2025 vision

Transforming video data: Videonetics 2025 vision

Genetec's state of physical security report 2026

Genetec's state of physical security report 2026

Secure Logiq expands APAC with DAS partnership

Secure Logiq expands APAC with DAS partnership

Follow us

Sections Products CCTV Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cyber security special report Casino security & surveillance RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Counter terror Cyber security Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy
  1. Home
  2. Topics
  3. Video analytics
  4. News
  5. Corporate news
About this page

Enhance multi-factor authentication effectiveness. Discover how managed service providers can improve client MFA security to prevent breaches and ensure stronger protection against cyber threats.

See this on SecurityInformed.com

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SourceSecurity.com - Making the world a safer place
Copyright © Notting Hill Media Limited 2000 - 2025, all rights reserved

Our other sites:
SecurityInformed.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
One system, one card
One system, one card
Understanding AI-powered video analytics
Understanding AI-powered video analytics
Security and surveillance technologies for the casino market
Security and surveillance technologies for the casino market
Modernizing access control
Modernizing access control
SourceSecurity.com
SecurityInformed.com

Browsing from the Americas? Looking for our US Edition?

View this content on SecurityInformed.com, our dedicated portal for our Americas audience.

US Edition International Edition
Sign up now for full access to SourceSecurity.com content
Download Datasheet
Download PDF Version
Download SourceSecurity.com product tech spec