Mayer Networks

Cybersecurity

MFA & Identity Protection

Identity is the modern perimeter. Mayer Networks implements multi-factor authentication, conditional access, privileged account separation and identity monitoring so a stolen password is not enough to enter your systems.

Security lifecycle

  1. Identify
  2. Protect (this page)
  3. Detect (this page)
  4. Respond
  5. Recover

MFA is a Protect control and identity threat detection is a Detect control. Together they cover the attack path that begins with a working password rather than malware. See the full Mayer Networks cybersecurity approach.

What it is

A Password Should Not Be Enough to Access Your Organization.

Most compromises we are called into begin with a valid credential, not with malware. Passwords are phished, reused, bought from previous breaches and guessed. Once one works, the attacker is inside as a legitimate user and much of the security stack has no reason to object.

Multi-factor authentication adds a second verification factor, so a stolen password on its own does not open email, remote access or administrative systems. Identity threat detection and response, or ITDR, watches identity behaviour after sign-in: suspicious authentication, unexpected persistence, mailbox rule changes, privilege changes and account abuse.

Identity is the perimeter now. It deserves the same attention the firewall used to receive.

The problem it solves

What Identity Security Is There to Stop

These are the attack paths that a password alone cannot close.

  • A phished Microsoft 365 password used to read and send mail as a staff member
  • Remote access protected by a single credential
  • Administrative accounts used for daily work
  • Attackers creating persistence: new app registrations, mailbox rules or added devices
  • Security settings quietly changed after an account is taken over
  • MFA fatigue, where a user approves a prompt they did not initiate

How Mayer Networks uses it

How Mayer Networks Implements Identity Protection

Rollouts fail when they surprise people. The implementation detail is what decides whether the control holds.

  • Inventory first

    Every account is identified, especially administrative and service accounts, along with where each is allowed to sign in from.

  • Planned rollout

    MFA is enforced in a communicated sequence with support available, so adoption succeeds instead of generating exceptions that hollow out the policy.

  • Close the bypasses

    Legacy authentication protocols are blocked where possible, because they route around the requirement entirely, and number matching is used to counter approval fatigue.

  • Conditional access

    Where the tenant supports it, sign-in is restricted by device, location or risk level so trusted work is smooth and risky sign-ins are challenged or blocked.

  • Privileged accounts

    Administrative access is separated from daily accounts, break-glass access is documented and protected, and service accounts get restrictions rather than blanket exemptions.

  • Identity monitoring

    Identity alerts feed the detection workflow, so an impossible-travel sign-in or a new forwarding rule is investigated rather than logged.

Platform

The Platforms We Use

Which platform fits depends on what the organization already licenses and what needs protecting beyond Microsoft 365.

Duo

Duo

Multi-factor authentication

MFA across remote access, VPN, servers and applications, including systems outside Microsoft 365. Useful where authentication has to cover more than the Microsoft tenant.

Microsoft Entra ID MFA and Conditional Access

Identity in the Microsoft tenant

MFA and conditional access policies inside Microsoft 365, configured against the licensing the organization holds. Frequently the right starting point for Microsoft-centric environments.

Huntress ITDR

Identity threat detection and response

Detection of suspicious identity behaviour in Microsoft 365, including unexpected persistence and account abuse, feeding the same investigation workflow as endpoint detections.

Duo is a Cisco product. Microsoft and Entra are trademarks of Microsoft Corporation. Mayer Networks is not affiliated with or endorsed by these vendors.

Layered defence

What MFA Does Not Replace

MFA removes the largest single category of incident. It does not cover the others.

  • Endpoint security, because malware does not need to sign in
  • Email security, which handles the message before anyone is asked for a password
  • Monitoring, because some sessions and tokens are stolen after authentication
  • Backup and recovery, which is what restores data an authorized-looking account destroyed
  • User awareness, because approval prompts still get approved

Identity is the highest-value single control on most roadmaps, and it is still one layer of several.

Cybersecurity overview: the layered Mayer Networks standard

Lifecycle stage: Protect and Detect

The layers most closely connected to this one. Each covers a front this control does not.

We can review where MFA is enforced today, which accounts are exempt, and whether legacy authentication is still leaving a way around it.

Review Identity and MFA Coverage

The single control that removes the most incidents

Most compromises we are called into begin with a valid credential rather than malware. Multi-factor authentication on email, remote access and administrative accounts removes the majority of that category, and it is inexpensive relative to almost anything else on a security roadmap.

Implementation detail decides whether it holds. Legacy authentication protocols must be blocked or they bypass the requirement entirely; service and shared accounts need a plan rather than an exemption; break-glass administrative access must exist and be documented before it is needed; and push fatigue is countered with number matching rather than by asking people to be more careful.

Why Mayer Networks

  • Rollouts planned to avoid locking people out of their work
  • Administrative access handled as carefully as user access
  • One organization accountable for support, engineering, security, infrastructure and communications.
  • Responsive remote and onsite support from engineers based in Southern Illinois, not a queue in another time zone.

Security considerations

  • Phishing-resistant methods preferred where supported
  • Break-glass administrative accounts documented and protected
  • Legacy authentication disabled where possible

Questions

Frequently asked questions

Still have a question? Call 618-529-4922 or send us the details.

Will MFA frustrate our staff?

A well-planned rollout keeps prompts infrequent for trusted devices while still protecting risky sign-ins.

Is text-message MFA good enough?

It is far better than nothing, but app-based or hardware methods resist interception and are preferred.

Does MFA cover our line-of-business applications?

Where those applications support modern authentication, yes. Where they do not, other controls such as network restrictions apply.

What about service accounts?

Service accounts are inventoried, restricted, given strong credentials and monitored, since they usually cannot use MFA.

Let's talk about your technology

Tell us what you are running and what is not working. We will tell you plainly what we would do about it.