Skip to content
Resource Library
Identity 6 min read

MFA coverage: the one identity metric that matters

Why account takeover starts with the accounts you forgot, how to measure coverage across your identity provider, and the admin-without-MFA problem.

The metric, defined precisely

MFA coverage is the percentage of accounts in your identity provider that have a second factor registered and enforced. Both words carry weight. Registered means the user actually completed enrollment — not that a policy exists somewhere saying they should. Enforced means sign-in fails without it — no grace periods that became permanent, no legacy protocols that skip the check entirely.

Credential attacks remain the front door of most breaches — phished passwords, reused passwords bought in bulk, sprayed passwords against login pages. MFA is the single control that makes a stolen password insufficient, which is why coverage — not "do we have MFA?" but "what percentage of accounts does it actually protect?" — is the identity number worth tracking weekly.

Why the gap hides in the accounts you forgot

Nobody's MFA gap lives in the accounts they think about. It lives at the edges: the contractor onboarded in a hurry, the shared mailbox that turned into a login, the service account a human uses interactively, the executive who got an exemption "temporarily" during a device swap, the break-glass admin account created during an incident and never cleaned up. Every one of these is invisible in a policy review and obvious in a per-account audit.

Attackers enumerate; that's the whole game. They don't need the accounts you protected — they need one you forgot. This is why coverage must be measured from the identity provider's actual data, account by account, rather than inferred from the existence of a conditional access policy.

The admin-without-MFA problem

Weight the metric by privilege. One admin account without MFA outweighs fifty standard users, because the compromise of that single account is the whole environment: the attacker inherits the ability to create accounts, alter policies, read everything, and erase their tracks. "Admins without MFA" deserves to be its own tracked number, and its only acceptable value is zero — including the emergency-access accounts, which should have the strongest factors you own, not exemptions.

Factor quality matters most at the top, too. Phishing-resistant methods — passkeys, FIDO2 security keys — belong on admin accounts first, since attackers who can't phish a code will happily proxy one through a fake login page.

Measuring it continuously

Every major identity provider exposes per-account MFA registration through its API — Entra ID, Okta, JumpCloud, OneLogin, Ping, Google Cloud Identity. The failure mode is checking once, fixing the list, and letting drift resume; every new hire and every exemption erodes coverage silently. Continuous measurement turns the metric into an alarm: coverage dips, a finding opens, someone fixes it while it's one account instead of forty.

Cybermatic connects to your identity provider read-only, computes MFA coverage across every account, flags admins-at-risk as findings, and feeds the numbers into your compliance scores — so the one identity metric that matters is always current, and always someone's job.

Security Essentials, Weekly

A practical weekly briefing on real-world security misconfigurations, why they matter, and how to fix them.

One email a week, unsubscribe any time. We use your address only to send the briefing — see our Privacy Policy.