Back to Resources
SecurityPublished Updated 10 min read

Multi-Factor Authentication: Meeting NY DFS 500.12 Requirements

Since 1 November 2025, MFA is required for anyone accessing any of your information systems. Here's how to implement it effectively and stay compliant.

Section 500.12 of NY DFS 23 NYCRR 500 requires covered entities to use multi-factor authentication (MFA). The Second Amendment, adopted in November 2023, replaced the old risk-based rule with a much broader one, which has applied in full since 1 November 2025.

What Does Section 500.12 Require?

Under the current regulation (500.12(a)), MFA is required for any individual accessing any of your information systems. If you qualify for the limited exemption in 500.19(a), MFA is required for:

  • Remote access to your information systems
  • Remote access to third-party applications, including cloud-based ones, from which nonpublic information is accessible
  • All privileged accounts, other than service accounts that prohibit interactive login

If you have a CISO, the CISO may approve in writing reasonably equivalent or more secure compensating controls, which must be reviewed at least annually (500.12(b)).

2023 Amendment Changes

The November 2023 amendment gave covered entities two years to meet the new MFA rule (500.22(d)(4)). Since 1 November 2025, MFA covers every individual accessing any information system, not just remote access to internal networks. That includes employees on the office network, cloud services and SaaS applications. The old option of "risk-based authentication" was removed.

What Qualifies as MFA?

Multi-factor authentication requires at least two of the following factors:

Something You Know

Password, PIN, security questions

Something You Have

Phone, hardware token, smart card

Something You Are

Fingerprint, facial recognition, voice

Acceptable MFA Methods

Not all MFA methods provide equal security. Here's a breakdown:

Recommended Methods

  • Hardware security keys (FIDO2/WebAuthn) - Most secure option
  • Authenticator apps (Microsoft Authenticator, Google Authenticator) - Strong and practical
  • Push notifications - Convenient with good security

Acceptable but Less Secure

  • SMS-based codes - Vulnerable to SIM swapping. The amended MFA definition (500.1(j)) no longer lists a text message as an example of a possession factor, so treat SMS as a fallback only
  • Email-based codes - Only if email itself is protected by MFA

Implementation Strategy

Follow these steps to implement MFA across your organization:

  1. Inventory your systems - Identify all systems requiring MFA protection
  2. Choose your MFA solution - Consider Microsoft 365, Okta, Duo, or similar platforms
  3. Start with privileged users - Implement MFA for admins and IT staff first
  4. Roll out to all users - Expand to every individual accessing any information system, on-site or remote
  5. Address third-party access - Ensure vendors and contractors use MFA
  6. Train your users - Provide clear instructions and support
  7. Monitor and enforce - Track MFA adoption and enforce compliance

Common Challenges and Solutions

User Resistance

Some employees may resist MFA as inconvenient. Address this by explaining the security benefits, providing training, and choosing user-friendly methods like push notifications.

Legacy Systems

Older systems may not support modern MFA. Consider using a VPN or identity proxy that adds MFA in front of legacy applications.

Lost Devices

Have a recovery process in place for when users lose their MFA devices. This should include identity verification before resetting MFA.

Buffalo Sentinel MFA Tracking

Our platform monitors MFA enrollment status across your organization and integrates with Microsoft 365, Okta, and other identity providers to provide real-time compliance visibility.

Documentation Requirements

For compliance purposes, maintain records of:

  • MFA enrollment status for all users
  • Systems protected by MFA
  • MFA method used (app, hardware key, etc.)
  • Any exceptions, with the CISO's written approval of compensating controls and their annual review

Track Your MFA Compliance

Buffalo Sentinel integrates with your identity provider to track MFA enrollment and generate compliance reports.

Request a Demo