Home/Questions/Multi-factor authentication/MFA on client and RMM access
Multi-factor authentication

Is multi-factor authentication enforced for all access to clients' systems and remote monitoring and management (RMM) applications?

If you manage other people's environments, this is the question your entire submission turns on. An RMM tenant is a key ring, and carriers underwrite it as one.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether every technician path into a client environment requires a second factor: the remote monitoring and management platform, the professional services automation tool that carries client credentials, the shared administrative accounts in client tenants, and any standing access held in a client directory. It is asking about your access to other organisations, not about your own office.

Why it is underwritten

Supply-chain ransomware through managed service providers produced some of the largest single-event losses the cyber market has absorbed. One compromised RMM tenant deploys to every connected endpoint at once, so a carrier is not underwriting the chance of one loss but the chance of a correlated loss across every client you serve. Markets that write managed service providers at all now treat this control as a condition, and several will not quote without it.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Part of this answer lives in your own identity platform and part lives in the RMM vendor and in each client tenant. Where technician access is federated to your Entra ID, the enforcing control is yours and is measurable. Where technicians hold local accounts in the RMM platform or standing accounts in client tenants, the evidence has to come from those systems.

PlatformWhere the setting livesWhat has to be true
Entra IDConditional Access scoped to the RMM and PSA applications, where those platforms federate to your tenantAn enforced policy requiring a strong authentication strength for every technician, with no exclusions for on-call convenience
Entra IDCross-tenant access settings and the Granular Delegated Admin Privileges relationships you holdDelegated administrative relationships are inventoried and time-bound rather than standing, and the accounts that use them are covered by the policy
Entra IDGuest and external member accounts held in client directoriesWhere you appear as a guest in a client tenant, that client's policy governs the sign-in. Standing guest privilege you cannot see the policy for is an exposure you cannot evidence
RMM platformTechnician account list and authentication configuration in the vendor consoleEvery technician account enforces multi-factor, including vendor support and integration accounts. Insurance Posture does not read RMM platforms, so this is attested
Client tenantsShared or local administrative accounts you maintain in client environmentsNo shared credential without a second factor, and no break-glass account whose password lives in a document
Standing privilege is the real question underneath

Multi-factor on standing administrative access to fifty client tenants is better than no multi-factor, and it is still standing access to fifty client tenants. Carriers that understand this market are moving toward asking about just-in-time elevation and time-bound delegated relationships. Answering the current question well while moving toward time-bound access is the position that survives the next form revision.

What a defensible yes requires

  • Every technician path into a client environment is enumerated, including PSA credential stores and vendor support accounts.
  • Technician authentication is federated where possible, so one enforced policy governs rather than a per-platform patchwork.
  • Administrators of the RMM platform itself are held to a phishing-resistant factor, since that account is the highest-value credential you hold.
  • Delegated administrative relationships with client tenants are inventoried and time-bound rather than standing and permanent.
  • Shared credentials in client environments are eliminated or, where a client insists, documented with the client and covered by a second factor.

How this answer goes wrong

The failure that produces claims is the integration account. Technicians have multi-factor, the RMM platform enforces it, and a single service integration account with full deployment rights authenticates with an API key that has not rotated in three years. That account is not a technician, so it is not covered by the answer, and it can push a script to every managed endpoint.

The second failure is the client-side blind spot. You enforce your own policy rigorously and hold standing global administrator rights in twenty client tenants where the client controls the Conditional Access policy. You cannot evidence what you do not control, and answering yes for those tenants is a representation about someone else's configuration.

Frequently asked

Does this question apply if we are not an MSP?

Only if you access other organisations' systems as part of your service. A software vendor with support access to customer instances is asked the same question in different words, and should read it the same way.

Are integration and API accounts in scope?

They cannot present a second factor, so they are excluded in mechanism and very much in scope in substance. Inventory them, scope their permissions down, rotate their secrets, and be ready to describe them, because a claims review will find them.

How do carriers verify this after a loss?

Through the RMM platform audit log, which records which account deployed what and how it authenticated. It is one of the most complete audit trails in this market, which cuts both ways.

Is delegated admin through the partner programme acceptable?

Yes, and granular, time-bound delegated relationships are viewed more favourably than legacy standing delegated administration. Migrating away from standing full-tenant delegation is worth doing before your next renewal rather than after it.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture