ShelCron

Security & Compliance

MFA

Multi-factor authentication policies that protect privileged and user paths without blocking real work.

MFA is only useful if people can enroll, recover, and actually use it. We design factor policy by risk tier, configure enrollment and recovery flows, and tighten exceptions so MFA is not a sticker on a still-open admin backdoor.

Request a quote

Who it’s for

  • Teams enabling MFA for the first time
  • Orgs with MFA on users but not on admins
  • Companies standardizing factors after a near-miss

Problems we address

  • MFA exists on paper but not on privileged paths
  • Recovery processes create new social-engineering risk
  • Users bypass MFA through legacy protocols

Expected outcomes

  • Risk-tiered MFA policy for users and admins
  • Enrollment and recovery playbooks
  • Legacy protocol and exception cleanup

Capabilities

Concrete engineering capabilities included in a typical engagement for this service.

IdP MFA policy design

Admin / break-glass factor strategy

Phishing-resistant factor planning where appropriate

Legacy auth protocol restriction guidance

User communication templates

Exception register with owners and expiry

Technology

Representative technologies used for this service. Final stack depends on your estate.

  • Okta
  • Entra ID
  • Auth0
  • FIDO2 / WebAuthn
  • TOTP
  • Push authenticators

Architecture

Identity & access path

Users authenticate through an identity provider before reaching protected apps.

UserIdP / SSOAppAPIAudit logs

Deliverables

  • MFA policy document by role tier
  • Configured IdP MFA settings for scope
  • Enrollment and recovery runbooks
  • Exception list with review dates

Out of scope

  • Purchasing and distributing hardware tokens at scale
  • End-user device MDM rollouts

Timeline

Typical timeline

1–3 weeks

Timeline depends on scope, access, and dependencies—not a delivery guarantee.

Process

A clear delivery path from discovery through handover and optional support.

  1. 01

    Discovery

    Goals, constraints, success criteria, and current-state review.

  2. 02

    Architecture

    Target design, interfaces, risks, and delivery sequence.

  3. 03

    Implementation

    Incremental build with visible progress and documented decisions.

  4. 04

    Testing

    Functional checks, failure paths, and acceptance criteria validation.

  5. 05

    Deployment

    Controlled release to staging and production with rollback paths.

  6. 06

    Handover

    Runbooks, access notes, and operator/admin walkthrough.

  7. 07

    Support

    Optional hypercare window or retainer continuity after go-live.

Custom engagement

Pricing depends on architecture, traffic profile, and integration depth. Share your requirements for a scoped quote.

FAQ

Not by default. We match factor strength to risk—often starting with stronger factors for admins and sensitive apps.

Ready to build?

Tell us about your environment, constraints, and target outcomes. We’ll recommend a package or a scoped quote.