Danzell 2026
Danzell MFA Changes: What Trips UK Firms Up
Published 1 July 2026
What Danzell changed
The five controls list is unchanged but the wording around MFA is firmer:
- MFA on every cloud service – not just email.
- MFA on every administrative account, every time.
- Break-glass accounts must use a strong MFA method, not a stored password alone.
- SMS is still accepted but discouraged. Authenticator apps or hardware keys are preferred.
The accounts assessors check
- Microsoft 365 / Google Workspace user and admin accounts.
- Identity provider admin consoles (Entra ID, Okta, Google Cloud Identity).
- IaaS consoles (AWS root + IAM users, Azure subscriptions, GCP projects).
- SaaS admin portals for any in-scope cloud app.
- Remote access (VPN, SSH bastions, RDP gateways).
Common Danzell-era trip-ups
- Service accounts with stored credentials that bypass MFA – Danzell expects compensating controls (conditional access, IP allowlisting, secrets manager rotation).
- Legacy authentication still enabled on Exchange Online or POP/IMAP – disable it.
- One MFA method per user – have a backup method so a lost phone does not lock you out.
- Trusted device exemptions – under Danzell, "remember this device for 90 days" is not a substitute for MFA on each sign-in for admin accounts.
What to evidence
Conditional Access policy exports (M365), IAM MFA reports (AWS / GCP), or an exported user list with MFA status from your identity provider. See our Microsoft 365 checklist for the exact settings.
