Auditor of State Recommends Multi-Factor Authentication Best Practices
From the Ohio Auditor of State: The Importance of Multi-Factor Authentication
The Auditor of State's office continues to see a growing number of incidents where compromised accounts lead to unauthorized access to payroll platforms, vendor management portals, and other internal systems. Even a basic user account can provide an opening for malicious activity — once inside, attackers frequently use password reset functions to access additional systems, redirect payroll deposits, alter vendor banking information, or initiate fraudulent payments.
What is MFA? Multi-factor authentication requires users to provide two or more forms of verification before accessing a system — typically combining something you know (a password), something you have (an authentication app or token), and something you are (biometrics). By requiring multiple factors, MFA significantly reduces the risk that a stolen password alone can be used to gain unauthorized access.
Key recommendations:
- Implement MFA across all systems — including email, cloud applications, payroll platforms, vendor portals, remote access solutions, and any internet-facing application. No exceptions, including executive leadership and system administrators.
- Apply MFA to vendors and third parties — contractors, consultants, and managed service providers must meet the same MFA requirements as internal users.
- Limit exposure of sensitive portal functions — payroll change requests, direct deposit modification forms, and vendor banking updates should not be accessible through publicly exposed portals without strong authentication controls.
- Strengthen password reset controls — account recovery processes should not rely solely on email access as proof of identity. Incorporate MFA verification, identity validation, and administrative review for high-risk account changes.
- Monitor high-risk changes — changes to vendor banking information, payroll direct deposit details, and user access privileges should require independent verification and approval workflows.
Password-only security is no longer sufficient. Organizations should assume credentials may eventually be compromised and implement layered controls to prevent a single breach from enabling broader system access or financial fraud. These measures align with NIST and CIS cybersecurity frameworks and can significantly reduce the risk of payroll diversion, vendor payment fraud, and other cyber-related losses.