Most companies protect SSO and email with MFA, but leave SSH, RDP, databases and service accounts exposed.
Those are the systems attackers go after once they're inside.
Where MFA Usually Stops
- Linux servers reached over SSH keys or passwords.
- Windows servers over RDP.
- Local admin accounts.
- Legacy apps that don't support SAML or OIDC.
- Network devices, OT and industrial systems.
Why These Gaps Matter
- Lateral movement: after the first compromise, attackers hop between servers with stolen credentials.
Ransomware operators especially target RDP and admin credentials.
Approaches to Close the Gaps
- MFA at the operating system level: a PAM module on Linux, a credential provider on Windows.
- MFA at a jump host or gateway.
- Just-in-time access that requires MFA before credentials are released.
- Passwordless and decentralized identity approaches.
Challenges to Address
- Offline and air-gapped systems.
- Keeping automation and CI/CD working without human MFA prompts.
- User friction for engineers who log in to many servers a day.
Takeaway
MFA coverage should follow your most privileged access, not just your SaaS apps.
Next up: What Is PAM and Why Every Organization Needs It.
Want MFA on SSH, RDP and legacy systems? Book a 15-min demo of AuthNull.