Multi-Factor Authentication Requirements for NZ Businesses

Multi-factor authentication, shortened to MFA, means proving who you are with more than one kind of evidence before a system lets you in. A password on its own is one factor. Add a code from an app, a tap on a security key or a fingerprint, and a stolen password alone stops being enough for that sign-in.

 

The questions New Zealand businesses ask about multi-factor authentication are practical ones: whether they have to have it, who says so, what exactly counts and what it costs. The New Zealand answers are more specific than people expect.

This page covers what the Privacy Act and the Privacy Commissioner expect of a small business, what government guidance requires of agencies and why that matters to everyone else, what an MFA system should cover, which methods are strongest, and what it costs if you are already on Microsoft 365.

What is multi-factor authentication?

Multi-factor authentication is a sign-in process that requires at least two independent pieces of evidence, from different categories, before access is granted. When MFA is enforced for a sign-in, a stolen password alone is not enough. Phishable methods, stolen sessions, weak recovery and systems left without MFA can still let an attacker in, which is why the method and the coverage both matter.

What are the three authentication factors?

Something you know, such as a password or PIN. Something you have, such as a phone, a security key or a smart card. Something you are, such as a fingerprint or a face. Multi-factor authentication needs factors from at least two of those categories, which is why two passwords do not count: both come from the same category and fail the same way. MFA does not always mean a password followed by a second screen: a passkey can combine the device you hold with a PIN or fingerprint in a single step.

Is MFA the same as two-factor authentication?

Two-factor authentication is multi-factor authentication with exactly two factors, which is the common business setup. The terms are used interchangeably in practice, and the Privacy Commissioner uses both. The distinction only matters if somebody is selling you a third factor.

The three multi-factor authentication factors, with a password and a security question in the same column

Is multi-factor authentication required in New Zealand?

The Privacy Act requires reasonable safeguards for personal information and does not name multi-factor authentication. The Privacy Commissioner describes two-factor authentication as a bare minimum for small businesses and organisations that hold or share personal information digitally, and warns that a small business which has a cyber-related privacy breach without it should expect to be found in breach of the Privacy Act. Contracts, insurance terms and the services you use can add their own requirements, so check those too.

The Privacy Act 2020 itself does not mention multi-factor authentication, two-factor authentication, or passwords at all. Information privacy principle 5 asks only that personal information be protected by “such security safeguards as are reasonable in the circumstances to take”. What counts as reasonable is left to the circumstances, and the Commissioner has now said what that means for multi-factor authentication.

What the Privacy Commissioner actually said

In May 2025 the Office of the Privacy Commissioner published a short piece with an unusually direct message. It describes two-factor authentication as “a bare minimum we would expect for small businesses or organisations that hold or share personal information digitally”, and says a small business that has a cyber-related privacy breach without at least that should expect to be found in breach of the Privacy Act.

It also explains how the test works: what is reasonable “depends on the size of the organisation and the scale and sensitivity of the personal information they hold”. A sole trader with a client list and a medical practice with patient records are held to different standards. Both are expected to protect the personal information they hold digitally, and the Commissioner names two-factor authentication as the minimum for doing so.

The Commissioner’s security guidance says the same thing in fewer words: if your organisation holds or shares personal information digitally, “you should have multi-factor authentication (MFA) enabled”. For a business holding personal information digitally, that answers the core question.

Who the binding rules apply to

Two sets of government rules make multi-factor authentication mandatory for the organisations they cover. The NCSC’s Minimum Cyber Security Standards are, in its own words, “intended for GCISO-mandated agencies who will be required to implement them”. The New Zealand Information Security Manual applies to government departments and agencies. A private business is not directly bound by either, but a government contract or supplier agreement can bring their requirements with it, so check what you have signed. Both are published and free, and both give a detailed picture of what good multi-factor authentication looks like in this country, which is why the next section uses them.

What does New Zealand government guidance require for MFA?

The NCSC’s minimum standard for multi-factor authentication, published in October 2025, sets out four maturity levels and names the second as “the expected minimum implementation level”. Each level builds on the one before.

Level What the NCSC minimum standard describes
CMM 1, Informal MFA is available on some systems and users have to turn it on themselves. No oversight or auditing of MFA use.
CMM 2, Planned and Tracked. The stated minimum. MFA is used for business-critical and externally facing systems, and when authenticating to third-party services. Privileged users are required to have MFA. All unsuccessful MFA attempts are logged, retained and reviewed.
CMM 3, Standardised Adds core network access. Privileged users are required to use MFA and it cannot be bypassed unless within a managed break glass scenario.
CMM 4, Quantitively Controlled MFA is required for all entities across all systems. All successful and unsuccessful MFA attempts are logged, retained and reviewed.

 

One correction worth making, because it circulates. The line about MFA not being bypassable except in a break glass scenario is sometimes quoted as the minimum. It belongs to level 3. The minimum is level 2. Level 3 adds core network access, and removes the ability of privileged users to bypass the control outside a managed emergency. Treat that as the scope of this framework, not as permission to leave privileged-account bypasses unmanaged.

What the NZISM makes mandatory

The New Zealand Information Security Manual, version 3.9, sets several multi-factor authentication controls as a MUST for the agency systems and user accounts it covers:

  • External, cloud and third-party systems. Where an agency has externally facing systems, cloud services, or authenticates to third-party services, it must require MFA for all user accounts (16.7.42.C.01).
  • Administrative accounts. MFA is required for administrative and other high-privileged users (16.7.42.C.02), and privileged accounts on admin portals reachable from the internet must use multiple factors (23.3.19.C.01).
  • Remote access. Every user account with remote access to organisational resources must use MFA (16.7.42.C.03).
  • No knowledge-based questions. Agencies must remove knowledge-based questions from the authentication process altogether (16.1.31.C.04).

 

The NZISM does not bind a private business, but it is a useful test. If your email, files and accounts sit in Microsoft 365 or Xero, those are cloud services, and the agency rule for cloud services covers every user account on them. That rule is about people signing in. Service accounts and automated connections between systems need different controls, such as managed credentials and restricted access.

Phishing-resistant multi-factor authentication is a SHOULD rather than a MUST, recommended for administration accounts (16.7.42.C.05) and for authenticating users generally (16.7.42.C.06). That is the next step up rather than the baseline, and it is covered below.

Email, files, accounting, customer records, payroll and remote access, each needing multi-factor authentication enforced

How effective is multi-factor authentication?

Very effective, though not a guarantee. A 2023 Microsoft study of commercial Microsoft Entra accounts estimated that multi-factor authentication reduced compromise risk by 99.22 per cent overall.

The more useful figure is the second one. For accounts whose credentials had already leaked, the same study estimated a 98.56 per cent reduction in risk. That is the scenario that matters, because a business should assume some staff passwords are already out there. The findings support the value of MFA but are not a guarantee for every method, application or business. It also found that accounts protected by SMS codes were compromised noticeably more often than those using an authenticator app, which is a point the next section comes back to.

What the New Zealand evidence says

The NCSC’s Cyber Threat Report 2025 puts it plainly: compromised credentials “are a common way for malicious actors to gain initial access”, and enforcing password policies and multi-factor authentication “is one of the simplest mitigations”. Common, not the most common. The same year’s reporting data had phishing and credential harvesting as the second-largest category of incidents, behind scams and fraud, and most reports overall came from individuals rather than businesses.

The report also carries a case that makes the point without a statistic. In May 2025 a New Zealand health sector organisation was hit by ransomware, and the investigation found that “a lack of MFA on an important service had enabled a threat actor to gain access”. One service.

Which MFA methods are strongest?

Physical security keys first, then app-based approvals, with SMS codes last. The NCSC’s Critical Control on multi-factor authentication lists the “something you have” options in what it calls “preferred order”:

  • Hardware security keys, which plug in or tap against a phone.
  • Authenticator apps with an approve or deny push notification.
  • Key fobs that generate a one-time code.
  • Authenticator apps that generate a one-time code.

 

On SMS it is blunt: avoid methods that are easy to bypass, “like OTP over SMS”. It also says that if a weaker method is your only option, “it’s better than not having MFA at all”. That is the right way to think about it. SMS on an account is a reason to plan a change, not a reason to leave the account unprotected in the meantime.

A dated note for Microsoft 365 users, September 2026. Microsoft has announced that passkeys became the default from 1 September 2026, with users enabled for SMS or voice prompted to register one. From 1 February 2027 it will stop providing SMS and voice codes itself for most users, with Global Administrators and external users following on 1 July 2027, and anyone relying only on SMS or voice will be asked to register a passkey to keep signing in. Check your own tenant notices and settings rather than assuming the change has reached you. Our passkeys guide covers the move.

What phishing-resistant means

Ordinary multi-factor authentication verifies the person but not the website. A convincing fake sign-in page can collect a password and a one-time code, pass both straight through to the real service, and keep the session. Phishing-resistant methods bind the sign-in to the genuine web address, so a FIDO2 security key or passkey presented to a fake site will not complete the sign-in. Not every physical token qualifies: a key fob that displays a code can be phished like any other code.

The NZISM lists FIDO2 or WebAuthn, smart cards and certificate-based authentication as phishing-resistant methods. Passkeys are built on the same FIDO2 standard, which is why they are a practical route to phishing resistance for many businesses rather than handing out hardware keys to everyone.

For push notifications, turn on number matching, where the person has to type a number shown on the sign-in screen rather than just tapping approve. It is not in the NCSC’s list, but it reduces the risk from attackers who send approval requests until somebody gives in. It does not make push approvals phishing-resistant.

A note on security questions

The Privacy Commissioner’s security guidance lists security questions among its examples of a second factor. New Zealand government guidance goes the other way: NZISM control 16.1.31.C.04 requires agencies to remove knowledge-based questions from authentication entirely. The answers to them can be findable online, and we would not rely on them.

What should a multi-factor authentication system cover?

Start with the systems staff actually sign in to: email, accounting, payroll, remote access and administration portals. For each one, check which methods it supports, whether multi-factor authentication is enforced rather than just available, and how account recovery works.

An authenticator app or security key provides the method, but each service or identity provider has to enforce the sign-in policy. Protecting Microsoft 365 does not automatically protect every other business login unless those apps sign in through it. Include guest and contractor accounts, and give service accounts and automated connections that cannot complete MFA their own controls.

How much does multi-factor authentication cost in Microsoft 365?

Basic multi-factor authentication capability is available without an extra Microsoft Entra licence. The cost depends on whether you need Conditional Access, additional licences or hardware keys, and on the work to configure applications, enrol staff and set up recovery.

Every Microsoft 365 tenancy can use a baseline setting Microsoft calls security defaults. Microsoft says it might be enabled in tenants created on or after 22 October 2019, so check your tenant rather than assuming. Security defaults require everyone to register for MFA, prompt administrators at every sign-in and prompt other users when Microsoft judges it necessary, with very little room to adjust.

Conditional access is the step up. It lets you decide when multi-factor authentication is required, block sign-ins from unmanaged devices or unexpected countries, and require stronger methods for administrators. It needs Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium but not in Business Basic or Business Standard. Conditional Access replaces security defaults rather than sitting on top of them, so equivalent protection has to stay in place during the switch.

Passkeys and FIDO2 security keys are a separate decision. Microsoft documents passkeys as available in every Microsoft Entra ID edition, including Free, so enabling them needs no extra licence. Conditional Access is what lets you require them for particular sign-ins.

So the answer to “what does MFA cost” starts with a question back: which licences are assigned, and which policies are actually enforced? A business on Business Standard has MFA and passkeys available but no Conditional Access. Check both before buying more. Beyond licensing, the costs are application compatibility work, rollout, staff support, recovery arrangements and any hardware keys.

Which Microsoft 365 plans include basic multi-factor authentication and which also include conditional access

Common multi-factor authentication mistakes

Five gaps to check for, none of them a failure of the technology itself.

  • Leaving admin accounts until last. Administrators can end up last to be enrolled because they trust themselves. Both the NCSC and the NZISM treat privileged accounts as the first priority, and they should get the strongest method you have.
  • Protecting email and stopping. The accounting platform, the CRM, the payroll system and the remote access tool all need it. For agencies, the NZISM rule covers every cloud and third-party service, and the same logic applies to a business.
  • SMS on the accounts that matter most. Acceptable as a stopgap, not on administrators or anyone approving payments.
  • No defence against approval spam. An attacker with the password can send push requests until somebody taps approve out of irritation. Number matching reduces this risk, and Conditional Access can require a stronger method.
  • A weak reset process. If the help desk will reset somebody’s multi-factor authentication on the strength of a phone call, the reset process becomes an easy way in. A written process helps only if it includes real identity checks, limits who can reset, and staff follow it. The NZISM says single-factor authentication should not be used when changing someone’s MFA details (16.1.36.C.03).

 

The fourth and fifth are both people problems as much as technical ones, which is why they sit alongside social engineering rather than in a settings screen.

How do you roll out MFA across a small business?

In stages, starting with the accounts that would do the most damage, and with recovery planned before the first person loses their phone. Timing depends on which applications support MFA, the number of users and devices, any legacy connections and how recovery will work, so pilot changes before they reach everyone.

  • List every system with its own sign-in, who can access it, and whether multi-factor authentication is on, including guest, contractor and emergency access accounts. Disable accounts for people who have left while you are there.
  • Plan recovery before enrolment: who can reset someone’s MFA, how they confirm identity first, where it is logged, and what happens for staff without a suitable personal phone.
  • Choose methods by risk. Authenticator app with number matching for most staff, security keys or passkeys for administrators and anyone who can move money.
  • Start with administrators and managers, then a pilot team, then everyone. Each wave shows you what the instructions need to say.
  • Enforce, then check. If your plan includes Conditional Access, it replaces security defaults, so plan the switch with no gap in protection. Block legacy sign-in methods that cannot do MFA, then confirm that policies actually require MFA, not just that people have registered a method.

 

Multi-factor authentication is also the foundation of zero trust security, and it appears on both of the NCSC’s lists, the Critical Controls and the Minimum Cyber Security Standards. If you are doing one thing this quarter, this is the one.

Frequently Asked Questions

What is multi-factor authentication in simple terms?

Multi-factor authentication means proving who you are with at least two different kinds of evidence before a system lets you in: something you know, such as a password, plus something you have, such as a phone or security key, or something you are, such as a fingerprint. When MFA is enforced for a sign-in, a stolen password on its own is not enough, because the attacker also needs the second factor.

Is multi-factor authentication required by law in New Zealand?

The Privacy Act 2020 does not name it. The Act asks for security safeguards that are reasonable in the circumstances. The Privacy Commissioner describes two-factor authentication as a bare minimum for small businesses holding or sharing personal information digitally, and warns that a small business with a cyber-related privacy breach and no two-factor authentication should expect to be found in breach of the Privacy Act.

What does the Privacy Commissioner expect?

At least two-factor authentication for any organisation that holds or shares personal information digitally. The Commissioner describes it as a bare minimum for small businesses, and its security guidance says such organisations should have multi-factor authentication enabled. What else is reasonable depends on the size of the organisation and the scale and sensitivity of the personal information it holds.

What does the NCSC minimum standard for MFA require?

The minimum is maturity level 2, Planned and Tracked: multi-factor authentication on business-critical and externally facing systems and third-party services, required for privileged users, with failed attempts logged and reviewed. The standard is intended for GCISO-mandated government agencies, but it is published and free, and it is a sensible benchmark for any organisation. The wording about MFA not being bypassable except in a break glass scenario belongs to level 3, not the minimum.

What is the difference between MFA and 2FA?

Two-factor authentication uses exactly two factors, and multi-factor authentication means two or more. In practice business deployments generally use two, so the terms are used interchangeably, including by the Privacy Commissioner. The security principle is the same either way: the second factor has to come from a different category to the first.

Which type of MFA is strongest?

Phishing-resistant methods: FIDO2 security keys and passkeys, both built on the FIDO2 standard, which bind the sign-in to the genuine website so they will not work on a fake one. The NCSC lists security keys first in its preferred order, followed by authenticator apps with push approval, key fobs and then app-generated codes. The NZISM recommends phishing-resistant MFA for administration accounts and for users generally.

Is SMS-based MFA safe?

It is the weakest common method, and the NCSC advises avoiding it where you can because codes can be intercepted, including through SIM swapping. But the NCSC also says that if a weaker method is your only option, it is better than having no MFA at all. Use it as a stopgap and move away from it, starting with administrators and anyone who can approve payments. Microsoft has also announced it will stop providing SMS and voice codes itself for most Microsoft 365 users from February 2027.

Can multi-factor authentication be bypassed?

Ordinary methods can be, through fake sign-in pages that relay codes in real time, repeated push requests until somebody approves one, SIM swapping against SMS, and weak reset processes. Phishing-resistant methods resist the relay attack, number matching reduces approval spam, and a reset process with real identity checks narrows the help desk route. Even ordinary MFA makes an account much harder to take over than a password alone.

How effective is multi-factor authentication?

A 2023 study by Microsoft researchers of commercial Microsoft Entra accounts estimated that multi-factor authentication reduced compromise risk by 99.22 per cent overall and by 98.56 per cent for accounts with leaked credentials. The same study found SMS-protected accounts were compromised noticeably more often than those using an authenticator app. The NCSC calls MFA one of the simplest mitigations against credential-based access.

Does Microsoft 365 include MFA at no extra cost?

Yes, at a basic level. Security defaults provide baseline MFA without an extra licence, and passkeys are available in every Microsoft Entra ID edition. Conditional Access, which lets you decide when and how MFA is required, needs Microsoft Entra ID P1, included in Business Premium but not in Business Basic or Business Standard. Check your tenant, because security defaults are not switched on in every tenancy.

Are security questions a good second factor?

No. They are something you know, the same category as a password, so a password plus a security question is not multi-factor. The answers can also be findable online. The NZISM requires government agencies to remove knowledge-based questions from authentication altogether, even though the security guidance from the Privacy Commissioner still lists them among its examples.

How long does it take to roll out MFA in a small business?

It depends on which applications support MFA, how many users and devices are involved, any legacy connections and how recovery will work. The work is listing every system with a sign-in, planning recovery, choosing methods by risk, and enrolling administrators first, then a pilot group, then everyone. A business already on Microsoft 365 has many of the technical pieces available, but they still need to be enforced and checked.

NEXT STEP

Find the accounts that are still one password away

Talk to Exodesk about multi-factor authentication and sign-in security through our cloud security services, available to businesses across New Zealand. If you would rather see where you stand first, request an IT assessment.

Or read more about our cyber security services.

Start typing and press Enter to search

Business systems inside and outside a broken network boundary, each one checked on its ownA laptop, tablet and phone on a desk, each showing the same business app layout Call Us Now