MMG
All case studies

Phishing resistant MFA and identity modernisation for a public health environment

Client persona
Regional Health Authority
Focus areas
Phishing resistant MFAZero Trust identity architectureEssential Eight complianceIdentity and access management

A large public health environment relied on SMS and email based MFA across a broad portfolio of internet facing applications, leaving identity as a material security exposure. The team assessed the application landscape, designed a phishing resistant authentication pathway on Microsoft Entra ID and built the operating processes needed to move clinical and corporate users without interrupting access to critical systems.

Representative experience delivered by the MMG Tech team within complex enterprise and public sector environments. Client details are withheld and outcomes are described without unverified metrics.

Why it mattered

Authentication had grown application by application. Many internet facing systems used SMS or email one time codes, some depended on legacy protocols, and a number were accessed through virtual desktops where modern authentication behaves differently.

Health services cannot simply switch access off. Any change to sign in had to protect clinicians and support staff working across shifts, sites and shared devices, while reducing exposure to credential phishing and MFA fatigue attacks.

  • SMS and email MFA vulnerable to phishing and interception
  • Legacy authentication and RADIUS dependent applications
  • VDI and shared workstation sign in constraints
  • Inconsistent joiner, mover and leaver handling
  • Limited visibility of which applications were ready to move

What was done and why

  1. 01

    Application assessment

    Each internet facing application was catalogued by authentication method, protocol, identity provider, user population and business criticality. This produced a readiness view showing which systems could adopt modern authentication immediately, which needed configuration change and which were constrained by vendor or protocol limitations.

  2. 02

    Identity architecture

    Microsoft Entra ID was positioned as the central identity provider, with Conditional Access policies designed around user risk, device state and application sensitivity. The target state followed Zero Trust principles: verify explicitly, apply least privilege and assume breach.

  3. 03

    Phishing resistant authentication

    FIDO2 security keys and passkeys were defined as the preferred authenticators, with Temporary Access Pass used for secure onboarding and recovery. Authentication strength policies were sequenced so higher risk users and applications moved first.

  4. 04

    Legacy and RADIUS constraints

    Applications relying on RADIUS or legacy protocols were separated into their own workstream. Options included the Entra network policy server extension, application proxy patterns, vendor upgrades and planned retirement, each assessed against risk and effort.

  5. 05

    VDI considerations

    Virtual desktop sign in was treated as a distinct scenario. The approach separated authentication at the gateway from authentication inside the session, so users were not prompted repeatedly and phishing resistant methods remained usable on shared endpoints.

  6. 06

    Joiner, mover and leaver processes

    Credential issuance, replacement and revocation were built into identity lifecycle processes, so new starters received authenticators on day one and leavers lost access promptly. Service desk procedures were defined for lost keys and account recovery.

  7. 07

    Governance and Essential Eight alignment

    A risk and benefits register tracked each phase, linking changes to the Essential Eight multi factor authentication control. Maturity was treated as something to be formally assessed, not assumed, and progress was reported against defined criteria.

What changed

  • A clear, prioritised pathway away from SMS and email based MFA
  • Reduced exposure to credential phishing for migrated users and applications
  • Documented handling for legacy, RADIUS and VDI constraints
  • Repeatable joiner, mover and leaver credential processes
  • Governance that links identity change to Essential Eight considerations

Working through something similar?

Tell us about your environment and constraints. We will respond with a practical next step.

Talk to an expert