Skip to main content
    NixInfinity-AI
    Danzell 2026

    Danzell MFA Changes: What Trips UK Firms Up

    Published 1 July 2026

    What Danzell changed

    The five controls list is unchanged but the wording around MFA is firmer:

    • MFA on every cloud service – not just email.
    • MFA on every administrative account, every time.
    • Break-glass accounts must use a strong MFA method, not a stored password alone.
    • SMS is still accepted but discouraged. Authenticator apps or hardware keys are preferred.

    The accounts assessors check

    • Microsoft 365 / Google Workspace user and admin accounts.
    • Identity provider admin consoles (Entra ID, Okta, Google Cloud Identity).
    • IaaS consoles (AWS root + IAM users, Azure subscriptions, GCP projects).
    • SaaS admin portals for any in-scope cloud app.
    • Remote access (VPN, SSH bastions, RDP gateways).

    Common Danzell-era trip-ups

    • Service accounts with stored credentials that bypass MFA – Danzell expects compensating controls (conditional access, IP allowlisting, secrets manager rotation).
    • Legacy authentication still enabled on Exchange Online or POP/IMAP – disable it.
    • One MFA method per user – have a backup method so a lost phone does not lock you out.
    • Trusted device exemptions – under Danzell, "remember this device for 90 days" is not a substitute for MFA on each sign-in for admin accounts.

    What to evidence

    Conditional Access policy exports (M365), IAM MFA reports (AWS / GCP), or an exported user list with MFA status from your identity provider. See our Microsoft 365 checklist for the exact settings.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions