6,3: Require MFA for Externally-Exposed Applications
Policy defined
Control implemented
Control automated
Control reported
Description
Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported. Enforcing MFA through a directory service or SSO provider is a satisfactory implementation of this Safeguard.